./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:09:04,048 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:09:04,050 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:09:04,072 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:09:04,072 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:09:04,075 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:09:04,076 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:09:04,077 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:09:04,078 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:09:04,079 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:09:04,079 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:09:04,080 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:09:04,080 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:09:04,081 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:09:04,082 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:09:04,083 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:09:04,083 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:09:04,084 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:09:04,085 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:09:04,086 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:09:04,090 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:09:04,091 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:09:04,092 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:09:04,093 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:09:04,095 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:09:04,098 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:09:04,099 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:09:04,099 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:09:04,100 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:09:04,101 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:09:04,101 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:09:04,101 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:09:04,102 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:09:04,103 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:09:04,104 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:09:04,104 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:09:04,105 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:09:04,105 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:09:04,105 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:09:04,106 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:09:04,106 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:09:04,107 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:09:04,125 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:09:04,125 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:09:04,125 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:09:04,126 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:09:04,126 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:09:04,126 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:09:04,127 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:09:04,127 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:09:04,127 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:09:04,127 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:09:04,127 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:09:04,127 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:09:04,128 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:09:04,129 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:09:04,129 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:09:04,129 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:09:04,129 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:09:04,129 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:04,129 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:09:04,129 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:09:04,130 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:09:04,131 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:09:04,131 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 [2021-12-17 15:09:04,306 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:09:04,335 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:09:04,338 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:09:04,339 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:09:04,339 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:09:04,340 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2021-12-17 15:09:04,405 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9f9434d91/825af23144304ee884f07a45eb657319/FLAG575aa5e73 [2021-12-17 15:09:04,848 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:09:04,849 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2021-12-17 15:09:04,870 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9f9434d91/825af23144304ee884f07a45eb657319/FLAG575aa5e73 [2021-12-17 15:09:05,375 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9f9434d91/825af23144304ee884f07a45eb657319 [2021-12-17 15:09:05,377 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:09:05,378 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:09:05,380 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:05,380 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:09:05,382 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:09:05,383 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,384 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@5254def9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05, skipping insertion in model container [2021-12-17 15:09:05,384 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,388 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:09:05,425 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:09:05,526 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2021-12-17 15:09:05,630 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:05,643 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:09:05,661 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2021-12-17 15:09:05,726 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:05,744 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:09:05,744 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05 WrapperNode [2021-12-17 15:09:05,745 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:05,746 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:05,746 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:09:05,746 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:09:05,751 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,774 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,806 INFO L137 Inliner]: procedures = 55, calls = 154, calls flagged for inlining = 24, calls inlined = 20, statements flattened = 257 [2021-12-17 15:09:05,807 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:05,807 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:09:05,807 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:09:05,807 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:09:05,813 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,813 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,814 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,814 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,818 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,821 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,822 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,824 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:09:05,825 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:09:05,825 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:09:05,825 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:09:05,826 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,845 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:05,851 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:05,861 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:09:05,878 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:09:05,886 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:09:05,886 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:09:05,887 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:09:05,887 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:09:05,888 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:09:05,951 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:09:05,953 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:09:06,177 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:09:06,182 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:09:06,182 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:09:06,183 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06 BoogieIcfgContainer [2021-12-17 15:09:06,183 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:09:06,184 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:09:06,184 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:09:06,186 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:09:06,186 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:09:05" (1/3) ... [2021-12-17 15:09:06,187 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@288887d2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:06, skipping insertion in model container [2021-12-17 15:09:06,187 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05" (2/3) ... [2021-12-17 15:09:06,187 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@288887d2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:06, skipping insertion in model container [2021-12-17 15:09:06,187 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06" (3/3) ... [2021-12-17 15:09:06,196 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product49.cil.c [2021-12-17 15:09:06,200 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:09:06,200 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:09:06,248 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:09:06,256 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:09:06,257 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:09:06,280 INFO L276 IsEmpty]: Start isEmpty. Operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-17 15:09:06,285 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2021-12-17 15:09:06,285 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:06,286 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:06,287 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:06,290 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:06,291 INFO L85 PathProgramCache]: Analyzing trace with hash -1722090408, now seen corresponding path program 1 times [2021-12-17 15:09:06,296 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:06,297 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [650954099] [2021-12-17 15:09:06,297 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:06,298 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:06,459 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:06,533 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:06,534 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:06,534 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [650954099] [2021-12-17 15:09:06,535 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [650954099] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:06,535 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:06,536 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:06,538 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1380794642] [2021-12-17 15:09:06,539 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:06,545 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:09:06,545 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:06,566 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:09:06,567 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:06,570 INFO L87 Difference]: Start difference. First operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,605 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:06,605 INFO L93 Difference]: Finished difference Result 156 states and 215 transitions. [2021-12-17 15:09:06,606 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:09:06,607 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2021-12-17 15:09:06,607 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:06,615 INFO L225 Difference]: With dead ends: 156 [2021-12-17 15:09:06,615 INFO L226 Difference]: Without dead ends: 73 [2021-12-17 15:09:06,618 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:06,620 INFO L933 BasicCegarLoop]: 104 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 104 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:06,621 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 104 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:06,637 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2021-12-17 15:09:06,653 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2021-12-17 15:09:06,654 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.3333333333333333) internal successors, (76), 64 states have internal predecessors, (76), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-17 15:09:06,658 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 95 transitions. [2021-12-17 15:09:06,661 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 95 transitions. Word has length 19 [2021-12-17 15:09:06,661 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:06,662 INFO L470 AbstractCegarLoop]: Abstraction has 73 states and 95 transitions. [2021-12-17 15:09:06,662 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,662 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 95 transitions. [2021-12-17 15:09:06,665 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2021-12-17 15:09:06,665 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:06,666 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:06,666 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:09:06,667 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:06,668 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:06,668 INFO L85 PathProgramCache]: Analyzing trace with hash 1895744144, now seen corresponding path program 1 times [2021-12-17 15:09:06,669 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:06,669 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1657604423] [2021-12-17 15:09:06,669 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:06,669 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:06,684 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:06,734 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:06,734 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:06,734 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1657604423] [2021-12-17 15:09:06,734 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1657604423] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:06,734 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:06,735 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:09:06,735 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1303370968] [2021-12-17 15:09:06,735 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:06,737 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:06,737 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:06,737 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:06,737 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:06,738 INFO L87 Difference]: Start difference. First operand 73 states and 95 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,749 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:06,750 INFO L93 Difference]: Finished difference Result 112 states and 146 transitions. [2021-12-17 15:09:06,750 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:06,751 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2021-12-17 15:09:06,751 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:06,752 INFO L225 Difference]: With dead ends: 112 [2021-12-17 15:09:06,752 INFO L226 Difference]: Without dead ends: 64 [2021-12-17 15:09:06,752 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:06,753 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 12 mSDsluCounter, 66 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 148 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:06,754 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 148 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:06,754 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2021-12-17 15:09:06,759 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2021-12-17 15:09:06,759 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3529411764705883) internal successors, (69), 58 states have internal predecessors, (69), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-17 15:09:06,763 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 83 transitions. [2021-12-17 15:09:06,763 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 83 transitions. Word has length 20 [2021-12-17 15:09:06,764 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:06,764 INFO L470 AbstractCegarLoop]: Abstraction has 64 states and 83 transitions. [2021-12-17 15:09:06,765 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,765 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 83 transitions. [2021-12-17 15:09:06,768 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-17 15:09:06,768 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:06,768 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:06,768 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:09:06,769 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:06,769 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:06,770 INFO L85 PathProgramCache]: Analyzing trace with hash 540813392, now seen corresponding path program 1 times [2021-12-17 15:09:06,770 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:06,770 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [417096217] [2021-12-17 15:09:06,771 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:06,771 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:06,794 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:06,858 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:06,859 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:06,859 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [417096217] [2021-12-17 15:09:06,859 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [417096217] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:06,859 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:06,859 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:06,859 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [721305039] [2021-12-17 15:09:06,860 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:06,860 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:06,860 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:06,860 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:06,861 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:06,861 INFO L87 Difference]: Start difference. First operand 64 states and 83 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,945 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:06,945 INFO L93 Difference]: Finished difference Result 121 states and 160 transitions. [2021-12-17 15:09:06,946 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:09:06,946 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2021-12-17 15:09:06,946 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:06,947 INFO L225 Difference]: With dead ends: 121 [2021-12-17 15:09:06,947 INFO L226 Difference]: Without dead ends: 64 [2021-12-17 15:09:06,948 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:06,948 INFO L933 BasicCegarLoop]: 76 mSDtfsCounter, 109 mSDsluCounter, 98 mSDsCounter, 0 mSdLazyCounter, 33 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 109 SdHoareTripleChecker+Valid, 174 SdHoareTripleChecker+Invalid, 43 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 33 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:06,950 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [109 Valid, 174 Invalid, 43 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 33 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:06,951 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2021-12-17 15:09:06,958 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2021-12-17 15:09:06,963 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3333333333333333) internal successors, (68), 58 states have internal predecessors, (68), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-17 15:09:06,964 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 82 transitions. [2021-12-17 15:09:06,965 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 82 transitions. Word has length 24 [2021-12-17 15:09:06,965 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:06,965 INFO L470 AbstractCegarLoop]: Abstraction has 64 states and 82 transitions. [2021-12-17 15:09:06,965 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:06,966 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 82 transitions. [2021-12-17 15:09:06,966 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2021-12-17 15:09:06,967 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:06,968 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:06,968 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:09:06,968 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:06,969 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:06,969 INFO L85 PathProgramCache]: Analyzing trace with hash 412315462, now seen corresponding path program 1 times [2021-12-17 15:09:06,969 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:06,969 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [488357873] [2021-12-17 15:09:06,969 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:06,969 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:06,983 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,007 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:07,009 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,020 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:07,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,024 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,024 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,025 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [488357873] [2021-12-17 15:09:07,025 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [488357873] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,025 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,025 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:07,025 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [933236433] [2021-12-17 15:09:07,025 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,026 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:07,026 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,026 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:07,026 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:07,027 INFO L87 Difference]: Start difference. First operand 64 states and 82 transitions. Second operand has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,180 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,180 INFO L93 Difference]: Finished difference Result 183 states and 235 transitions. [2021-12-17 15:09:07,181 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:07,181 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 34 [2021-12-17 15:09:07,181 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,182 INFO L225 Difference]: With dead ends: 183 [2021-12-17 15:09:07,182 INFO L226 Difference]: Without dead ends: 126 [2021-12-17 15:09:07,183 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:07,184 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 149 mSDsluCounter, 156 mSDsCounter, 0 mSdLazyCounter, 72 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 151 SdHoareTripleChecker+Valid, 267 SdHoareTripleChecker+Invalid, 103 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 72 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,184 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [151 Valid, 267 Invalid, 103 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 72 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,185 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 126 states. [2021-12-17 15:09:07,200 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 126 to 120. [2021-12-17 15:09:07,201 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 120 states, 96 states have (on average 1.28125) internal successors, (123), 103 states have internal predecessors, (123), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2021-12-17 15:09:07,202 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 120 states to 120 states and 148 transitions. [2021-12-17 15:09:07,202 INFO L78 Accepts]: Start accepts. Automaton has 120 states and 148 transitions. Word has length 34 [2021-12-17 15:09:07,202 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,202 INFO L470 AbstractCegarLoop]: Abstraction has 120 states and 148 transitions. [2021-12-17 15:09:07,202 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,202 INFO L276 IsEmpty]: Start isEmpty. Operand 120 states and 148 transitions. [2021-12-17 15:09:07,203 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-17 15:09:07,203 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,203 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,203 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:09:07,203 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,204 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,204 INFO L85 PathProgramCache]: Analyzing trace with hash 1451427371, now seen corresponding path program 1 times [2021-12-17 15:09:07,204 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,204 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1251638372] [2021-12-17 15:09:07,204 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,204 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,214 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,231 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:07,234 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,256 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,257 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,257 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1251638372] [2021-12-17 15:09:07,257 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1251638372] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,257 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,257 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:07,257 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [691076885] [2021-12-17 15:09:07,258 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,258 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:07,258 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,258 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:07,259 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:07,259 INFO L87 Difference]: Start difference. First operand 120 states and 148 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,342 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,342 INFO L93 Difference]: Finished difference Result 241 states and 301 transitions. [2021-12-17 15:09:07,342 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:07,343 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2021-12-17 15:09:07,343 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,350 INFO L225 Difference]: With dead ends: 241 [2021-12-17 15:09:07,350 INFO L226 Difference]: Without dead ends: 128 [2021-12-17 15:09:07,351 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:09:07,352 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 59 mSDsluCounter, 257 mSDsCounter, 0 mSdLazyCounter, 84 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 60 SdHoareTripleChecker+Valid, 339 SdHoareTripleChecker+Invalid, 101 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 84 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,352 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [60 Valid, 339 Invalid, 101 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 84 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,353 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 128 states. [2021-12-17 15:09:07,360 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 128 to 123. [2021-12-17 15:09:07,360 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 123 states, 99 states have (on average 1.2727272727272727) internal successors, (126), 106 states have internal predecessors, (126), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2021-12-17 15:09:07,360 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 123 states to 123 states and 151 transitions. [2021-12-17 15:09:07,361 INFO L78 Accepts]: Start accepts. Automaton has 123 states and 151 transitions. Word has length 38 [2021-12-17 15:09:07,361 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,361 INFO L470 AbstractCegarLoop]: Abstraction has 123 states and 151 transitions. [2021-12-17 15:09:07,361 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,361 INFO L276 IsEmpty]: Start isEmpty. Operand 123 states and 151 transitions. [2021-12-17 15:09:07,361 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-17 15:09:07,361 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,362 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,362 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:09:07,362 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,362 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,362 INFO L85 PathProgramCache]: Analyzing trace with hash 440310121, now seen corresponding path program 1 times [2021-12-17 15:09:07,362 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,362 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1017072547] [2021-12-17 15:09:07,362 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,362 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,377 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,388 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:07,391 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,402 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,402 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,403 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1017072547] [2021-12-17 15:09:07,403 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1017072547] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,403 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,403 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:07,403 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1044772301] [2021-12-17 15:09:07,403 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,403 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:07,403 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,403 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:07,403 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:07,404 INFO L87 Difference]: Start difference. First operand 123 states and 151 transitions. Second operand has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,460 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,461 INFO L93 Difference]: Finished difference Result 249 states and 312 transitions. [2021-12-17 15:09:07,461 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:09:07,461 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2021-12-17 15:09:07,461 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,462 INFO L225 Difference]: With dead ends: 249 [2021-12-17 15:09:07,462 INFO L226 Difference]: Without dead ends: 133 [2021-12-17 15:09:07,462 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:07,463 INFO L933 BasicCegarLoop]: 83 mSDtfsCounter, 61 mSDsluCounter, 183 mSDsCounter, 0 mSdLazyCounter, 63 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 63 SdHoareTripleChecker+Valid, 266 SdHoareTripleChecker+Invalid, 76 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 63 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,463 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [63 Valid, 266 Invalid, 76 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 63 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:07,464 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 133 states. [2021-12-17 15:09:07,470 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 133 to 125. [2021-12-17 15:09:07,471 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 125 states, 101 states have (on average 1.2673267326732673) internal successors, (128), 108 states have internal predecessors, (128), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2021-12-17 15:09:07,471 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 125 states to 125 states and 153 transitions. [2021-12-17 15:09:07,471 INFO L78 Accepts]: Start accepts. Automaton has 125 states and 153 transitions. Word has length 38 [2021-12-17 15:09:07,471 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,471 INFO L470 AbstractCegarLoop]: Abstraction has 125 states and 153 transitions. [2021-12-17 15:09:07,471 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,472 INFO L276 IsEmpty]: Start isEmpty. Operand 125 states and 153 transitions. [2021-12-17 15:09:07,472 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-17 15:09:07,472 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,472 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,472 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:09:07,472 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,473 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,473 INFO L85 PathProgramCache]: Analyzing trace with hash -580758233, now seen corresponding path program 1 times [2021-12-17 15:09:07,473 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,473 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [225635697] [2021-12-17 15:09:07,473 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,473 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,516 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:07,518 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,526 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,526 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,526 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [225635697] [2021-12-17 15:09:07,527 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [225635697] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,527 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,527 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:07,527 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [387949887] [2021-12-17 15:09:07,527 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,527 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:07,528 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,528 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:07,528 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:07,528 INFO L87 Difference]: Start difference. First operand 125 states and 153 transitions. Second operand has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,640 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,640 INFO L93 Difference]: Finished difference Result 355 states and 457 transitions. [2021-12-17 15:09:07,640 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:07,641 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2021-12-17 15:09:07,641 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,642 INFO L225 Difference]: With dead ends: 355 [2021-12-17 15:09:07,642 INFO L226 Difference]: Without dead ends: 237 [2021-12-17 15:09:07,643 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:07,643 INFO L933 BasicCegarLoop]: 124 mSDtfsCounter, 177 mSDsluCounter, 155 mSDsCounter, 0 mSdLazyCounter, 118 mSolverCounterSat, 44 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 181 SdHoareTripleChecker+Valid, 279 SdHoareTripleChecker+Invalid, 162 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 44 IncrementalHoareTripleChecker+Valid, 118 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,644 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [181 Valid, 279 Invalid, 162 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [44 Valid, 118 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,644 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2021-12-17 15:09:07,656 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 229. [2021-12-17 15:09:07,657 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 229 states, 181 states have (on average 1.2596685082872927) internal successors, (228), 192 states have internal predecessors, (228), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2021-12-17 15:09:07,658 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 229 states to 229 states and 289 transitions. [2021-12-17 15:09:07,658 INFO L78 Accepts]: Start accepts. Automaton has 229 states and 289 transitions. Word has length 38 [2021-12-17 15:09:07,658 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,658 INFO L470 AbstractCegarLoop]: Abstraction has 229 states and 289 transitions. [2021-12-17 15:09:07,659 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,659 INFO L276 IsEmpty]: Start isEmpty. Operand 229 states and 289 transitions. [2021-12-17 15:09:07,659 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2021-12-17 15:09:07,660 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,660 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,660 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:09:07,660 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,660 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,661 INFO L85 PathProgramCache]: Analyzing trace with hash -360899650, now seen corresponding path program 1 times [2021-12-17 15:09:07,661 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,661 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2081887982] [2021-12-17 15:09:07,661 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,661 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,694 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:07,697 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,700 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:07,701 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,702 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,703 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,703 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2081887982] [2021-12-17 15:09:07,703 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2081887982] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,703 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,703 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:07,703 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [128801808] [2021-12-17 15:09:07,703 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,704 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:07,704 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,704 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:07,704 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:07,704 INFO L87 Difference]: Start difference. First operand 229 states and 289 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,804 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,805 INFO L93 Difference]: Finished difference Result 451 states and 570 transitions. [2021-12-17 15:09:07,805 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:07,805 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 40 [2021-12-17 15:09:07,806 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,807 INFO L225 Difference]: With dead ends: 451 [2021-12-17 15:09:07,807 INFO L226 Difference]: Without dead ends: 229 [2021-12-17 15:09:07,807 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:09:07,808 INFO L933 BasicCegarLoop]: 76 mSDtfsCounter, 98 mSDsluCounter, 244 mSDsCounter, 0 mSdLazyCounter, 105 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 101 SdHoareTripleChecker+Valid, 320 SdHoareTripleChecker+Invalid, 125 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 105 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,808 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [101 Valid, 320 Invalid, 125 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 105 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,809 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 229 states. [2021-12-17 15:09:07,817 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 229 to 227. [2021-12-17 15:09:07,818 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 227 states, 179 states have (on average 1.2513966480446927) internal successors, (224), 190 states have internal predecessors, (224), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2021-12-17 15:09:07,819 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 227 states to 227 states and 285 transitions. [2021-12-17 15:09:07,819 INFO L78 Accepts]: Start accepts. Automaton has 227 states and 285 transitions. Word has length 40 [2021-12-17 15:09:07,819 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,819 INFO L470 AbstractCegarLoop]: Abstraction has 227 states and 285 transitions. [2021-12-17 15:09:07,819 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,820 INFO L276 IsEmpty]: Start isEmpty. Operand 227 states and 285 transitions. [2021-12-17 15:09:07,820 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2021-12-17 15:09:07,820 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,820 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,821 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:09:07,821 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,821 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,821 INFO L85 PathProgramCache]: Analyzing trace with hash 2038696205, now seen corresponding path program 1 times [2021-12-17 15:09:07,821 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,821 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1872984430] [2021-12-17 15:09:07,822 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,822 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,829 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,852 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:07,853 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,859 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-17 15:09:07,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,867 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,867 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,867 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1872984430] [2021-12-17 15:09:07,868 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1872984430] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,868 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,868 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:07,868 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [45909379] [2021-12-17 15:09:07,868 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,868 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:07,869 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,869 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:07,869 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:07,869 INFO L87 Difference]: Start difference. First operand 227 states and 285 transitions. Second operand has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:08,079 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:08,079 INFO L93 Difference]: Finished difference Result 456 states and 585 transitions. [2021-12-17 15:09:08,081 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-17 15:09:08,081 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 42 [2021-12-17 15:09:08,081 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:08,083 INFO L225 Difference]: With dead ends: 456 [2021-12-17 15:09:08,083 INFO L226 Difference]: Without dead ends: 276 [2021-12-17 15:09:08,083 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=63, Invalid=119, Unknown=0, NotChecked=0, Total=182 [2021-12-17 15:09:08,084 INFO L933 BasicCegarLoop]: 126 mSDtfsCounter, 159 mSDsluCounter, 358 mSDsCounter, 0 mSdLazyCounter, 241 mSolverCounterSat, 39 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 484 SdHoareTripleChecker+Invalid, 280 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 39 IncrementalHoareTripleChecker+Valid, 241 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:08,084 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [160 Valid, 484 Invalid, 280 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [39 Valid, 241 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:08,084 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 276 states. [2021-12-17 15:09:08,093 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 276 to 253. [2021-12-17 15:09:08,094 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 253 states, 201 states have (on average 1.2338308457711442) internal successors, (248), 215 states have internal predecessors, (248), 24 states have call successors, (24), 23 states have call predecessors, (24), 27 states have return successors, (41), 24 states have call predecessors, (41), 24 states have call successors, (41) [2021-12-17 15:09:08,095 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 253 states to 253 states and 313 transitions. [2021-12-17 15:09:08,095 INFO L78 Accepts]: Start accepts. Automaton has 253 states and 313 transitions. Word has length 42 [2021-12-17 15:09:08,095 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:08,095 INFO L470 AbstractCegarLoop]: Abstraction has 253 states and 313 transitions. [2021-12-17 15:09:08,095 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:08,095 INFO L276 IsEmpty]: Start isEmpty. Operand 253 states and 313 transitions. [2021-12-17 15:09:08,096 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2021-12-17 15:09:08,096 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:08,096 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:08,096 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:09:08,096 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:08,097 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:08,097 INFO L85 PathProgramCache]: Analyzing trace with hash 871440435, now seen corresponding path program 1 times [2021-12-17 15:09:08,097 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:08,097 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [27830777] [2021-12-17 15:09:08,097 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,097 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:08,109 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,133 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:08,134 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,140 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:08,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,161 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:08,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,167 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-17 15:09:08,167 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:08,167 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [27830777] [2021-12-17 15:09:08,168 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [27830777] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:08,168 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2143189416] [2021-12-17 15:09:08,168 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,168 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:08,168 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:08,169 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:08,174 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:09:08,260 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,262 INFO L263 TraceCheckSpWp]: Trace formula consists of 407 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-17 15:09:08,268 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:08,474 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:08,474 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:09:08,591 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:08,591 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2143189416] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:09:08,591 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:09:08,592 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2021-12-17 15:09:08,592 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [728645630] [2021-12-17 15:09:08,592 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:09:08,592 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2021-12-17 15:09:08,592 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:08,592 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2021-12-17 15:09:08,592 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:08,593 INFO L87 Difference]: Start difference. First operand 253 states and 313 transitions. Second operand has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2021-12-17 15:09:09,165 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:09,166 INFO L93 Difference]: Finished difference Result 628 states and 814 transitions. [2021-12-17 15:09:09,166 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2021-12-17 15:09:09,166 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) Word has length 69 [2021-12-17 15:09:09,167 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:09,170 INFO L225 Difference]: With dead ends: 628 [2021-12-17 15:09:09,170 INFO L226 Difference]: Without dead ends: 424 [2021-12-17 15:09:09,172 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 185 GetRequests, 145 SyntacticMatches, 1 SemanticMatches, 39 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 397 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=312, Invalid=1328, Unknown=0, NotChecked=0, Total=1640 [2021-12-17 15:09:09,172 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 476 mSDsluCounter, 726 mSDsCounter, 0 mSdLazyCounter, 676 mSolverCounterSat, 128 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 480 SdHoareTripleChecker+Valid, 857 SdHoareTripleChecker+Invalid, 804 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 128 IncrementalHoareTripleChecker+Valid, 676 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:09,173 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [480 Valid, 857 Invalid, 804 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [128 Valid, 676 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:09:09,173 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 424 states. [2021-12-17 15:09:09,191 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 424 to 355. [2021-12-17 15:09:09,192 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 355 states, 282 states have (on average 1.2234042553191489) internal successors, (345), 301 states have internal predecessors, (345), 34 states have call successors, (34), 33 states have call predecessors, (34), 38 states have return successors, (61), 32 states have call predecessors, (61), 34 states have call successors, (61) [2021-12-17 15:09:09,193 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 355 states to 355 states and 440 transitions. [2021-12-17 15:09:09,195 INFO L78 Accepts]: Start accepts. Automaton has 355 states and 440 transitions. Word has length 69 [2021-12-17 15:09:09,195 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:09,195 INFO L470 AbstractCegarLoop]: Abstraction has 355 states and 440 transitions. [2021-12-17 15:09:09,195 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2021-12-17 15:09:09,195 INFO L276 IsEmpty]: Start isEmpty. Operand 355 states and 440 transitions. [2021-12-17 15:09:09,197 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 104 [2021-12-17 15:09:09,197 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:09,197 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:09,218 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-17 15:09:09,417 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-17 15:09:09,418 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:09,418 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:09,418 INFO L85 PathProgramCache]: Analyzing trace with hash 1761843705, now seen corresponding path program 1 times [2021-12-17 15:09:09,418 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:09,418 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1036331692] [2021-12-17 15:09:09,418 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:09,418 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:09,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,476 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:09,478 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,484 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:09,486 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,493 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:09,494 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,497 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-17 15:09:09,498 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,507 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-17 15:09:09,508 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,509 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:09,510 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,511 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 52 trivial. 0 not checked. [2021-12-17 15:09:09,512 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:09,512 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1036331692] [2021-12-17 15:09:09,512 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1036331692] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:09,512 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [625683317] [2021-12-17 15:09:09,512 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:09,512 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:09,512 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:09,513 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:09,514 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:09:09,599 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,601 INFO L263 TraceCheckSpWp]: Trace formula consists of 491 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-17 15:09:09,603 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:09,847 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 53 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:09,847 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:09:10,068 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 51 proven. 9 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-12-17 15:09:10,068 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [625683317] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:09:10,068 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:09:10,069 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 9, 8] total 20 [2021-12-17 15:09:10,069 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1329576239] [2021-12-17 15:09:10,069 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,069 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2021-12-17 15:09:10,069 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,070 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2021-12-17 15:09:10,070 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=71, Invalid=309, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:09:10,070 INFO L87 Difference]: Start difference. First operand 355 states and 440 transitions. Second operand has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2021-12-17 15:09:11,378 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,379 INFO L93 Difference]: Finished difference Result 916 states and 1194 transitions. [2021-12-17 15:09:11,379 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 42 states. [2021-12-17 15:09:11,379 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) Word has length 103 [2021-12-17 15:09:11,379 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,382 INFO L225 Difference]: With dead ends: 916 [2021-12-17 15:09:11,382 INFO L226 Difference]: Without dead ends: 609 [2021-12-17 15:09:11,383 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 280 GetRequests, 226 SyntacticMatches, 1 SemanticMatches, 53 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 580 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=636, Invalid=2334, Unknown=0, NotChecked=0, Total=2970 [2021-12-17 15:09:11,384 INFO L933 BasicCegarLoop]: 245 mSDtfsCounter, 640 mSDsluCounter, 1442 mSDsCounter, 0 mSdLazyCounter, 1511 mSolverCounterSat, 218 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 647 SdHoareTripleChecker+Valid, 1687 SdHoareTripleChecker+Invalid, 1729 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 218 IncrementalHoareTripleChecker+Valid, 1511 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,384 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [647 Valid, 1687 Invalid, 1729 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [218 Valid, 1511 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2021-12-17 15:09:11,385 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 609 states. [2021-12-17 15:09:11,407 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 609 to 525. [2021-12-17 15:09:11,407 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 525 states, 411 states have (on average 1.2092457420924574) internal successors, (497), 435 states have internal predecessors, (497), 56 states have call successors, (56), 54 states have call predecessors, (56), 57 states have return successors, (91), 51 states have call predecessors, (91), 56 states have call successors, (91) [2021-12-17 15:09:11,409 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 525 states to 525 states and 644 transitions. [2021-12-17 15:09:11,409 INFO L78 Accepts]: Start accepts. Automaton has 525 states and 644 transitions. Word has length 103 [2021-12-17 15:09:11,410 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,410 INFO L470 AbstractCegarLoop]: Abstraction has 525 states and 644 transitions. [2021-12-17 15:09:11,410 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2021-12-17 15:09:11,410 INFO L276 IsEmpty]: Start isEmpty. Operand 525 states and 644 transitions. [2021-12-17 15:09:11,413 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2021-12-17 15:09:11,413 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:11,413 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:11,429 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-17 15:09:11,627 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:09:11,627 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:11,628 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:11,628 INFO L85 PathProgramCache]: Analyzing trace with hash 1113823743, now seen corresponding path program 1 times [2021-12-17 15:09:11,628 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:11,628 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2004095142] [2021-12-17 15:09:11,628 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:11,628 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:11,638 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,650 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:11,651 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,655 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:11,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,660 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:11,661 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,663 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-17 15:09:11,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,680 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-17 15:09:11,681 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,684 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:11,684 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,686 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 95 [2021-12-17 15:09:11,686 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,689 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:11,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,690 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 42 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2021-12-17 15:09:11,691 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:11,691 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2004095142] [2021-12-17 15:09:11,691 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2004095142] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:11,691 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:11,691 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-17 15:09:11,691 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [741858944] [2021-12-17 15:09:11,691 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:11,692 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:09:11,692 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:11,692 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:09:11,692 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:11,692 INFO L87 Difference]: Start difference. First operand 525 states and 644 transitions. Second operand has 8 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-17 15:09:11,803 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,804 INFO L93 Difference]: Finished difference Result 676 states and 824 transitions. [2021-12-17 15:09:11,804 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:09:11,804 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 110 [2021-12-17 15:09:11,804 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,805 INFO L225 Difference]: With dead ends: 676 [2021-12-17 15:09:11,805 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:09:11,806 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:11,806 INFO L933 BasicCegarLoop]: 68 mSDtfsCounter, 132 mSDsluCounter, 199 mSDsCounter, 0 mSdLazyCounter, 148 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 134 SdHoareTripleChecker+Valid, 267 SdHoareTripleChecker+Invalid, 180 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 148 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,807 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [134 Valid, 267 Invalid, 180 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 148 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:11,807 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:09:11,807 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:09:11,807 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:11,807 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:09:11,808 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2021-12-17 15:09:11,808 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,808 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:09:11,808 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-17 15:09:11,808 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:09:11,808 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:09:11,810 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:09:11,810 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2021-12-17 15:09:11,812 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:09:12,867 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 303 309) no Hoare annotation was computed. [2021-12-17 15:09:12,867 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 303 309) the Hoare annotation is: true [2021-12-17 15:09:12,867 INFO L858 garLoopResultBuilder]: For program point L97-1(lines 93 104) no Hoare annotation was computed. [2021-12-17 15:09:12,867 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 93 104) the Hoare annotation is: true [2021-12-17 15:09:12,867 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 93 104) no Hoare annotation was computed. [2021-12-17 15:09:12,867 INFO L858 garLoopResultBuilder]: For program point L283-1(lines 282 301) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point L345(lines 345 353) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point L341(lines 341 358) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point L73(lines 73 77) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point L585(lines 585 591) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L854 garLoopResultBuilder]: At program point L73-2(lines 69 80) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0))) [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 279 302) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L858 garLoopResultBuilder]: For program point L581(lines 581 594) no Hoare annotation was computed. [2021-12-17 15:09:12,868 INFO L854 garLoopResultBuilder]: At program point L581-1(lines 573 597) the Hoare annotation is: (let ((.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (and (<= 2 |timeShift_getWaterLevel_#res#1|) (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) .cse2 (<= 2 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (and .cse2 (< |old(~waterLevel~0)| 2) .cse3) .cse4 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) (<= 1 |timeShift_getWaterLevel_#res#1|) .cse3) .cse0 .cse4) (or (not (= |old(~waterLevel~0)| 1)) .cse1 (and (= |timeShift_getWaterLevel_#res#1| 1) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1)) .cse4)))) [2021-12-17 15:09:12,869 INFO L854 garLoopResultBuilder]: At program point L375(lines 370 377) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (= ~pumpRunning~0 0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,869 INFO L858 garLoopResultBuilder]: For program point L462(lines 462 466) no Hoare annotation was computed. [2021-12-17 15:09:12,869 INFO L858 garLoopResultBuilder]: For program point L462-2(lines 462 466) no Hoare annotation was computed. [2021-12-17 15:09:12,869 INFO L854 garLoopResultBuilder]: At program point L165(lines 160 168) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,869 INFO L854 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,869 INFO L858 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2021-12-17 15:09:12,869 INFO L854 garLoopResultBuilder]: At program point L356(line 356) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (and (= ~waterLevel~0 |old(~waterLevel~0)|) .cse0) (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse1))) [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point L356-1(lines 337 361) the Hoare annotation is: (let ((.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse0 (and .cse3 (<= 2 ~waterLevel~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) .cse1) .cse2) (or .cse0 (and .cse3 .cse1) (not (= |old(~pumpRunning~0)| 0)) .cse2 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L290-1(lines 290 296) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point L468(lines 453 471) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 279 302) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1) (or (and .cse0 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point L142(lines 137 145) the Hoare annotation is: (let ((.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (and (<= 2 |timeShift_getWaterLevel_#res#1|) .cse2 (<= 2 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (and .cse2 (< |old(~waterLevel~0)| 2) .cse3) .cse4 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 1 |timeShift_getWaterLevel_#res#1|) .cse3) .cse0 .cse4) (or (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1) .cse1 .cse4)))) [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 279 302) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L854 garLoopResultBuilder]: At program point L394(lines 389 397) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L193(line 193) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 172 201) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 172 201) the Hoare annotation is: true [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L186(lines 186 190) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L861 garLoopResultBuilder]: At program point L186-1(lines 186 190) the Hoare annotation is: true [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L183(line 183) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L861 garLoopResultBuilder]: At program point L182-2(lines 182 196) the Hoare annotation is: true [2021-12-17 15:09:12,870 INFO L861 garLoopResultBuilder]: At program point L178(line 178) the Hoare annotation is: true [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L178-1(line 178) no Hoare annotation was computed. [2021-12-17 15:09:12,870 INFO L861 garLoopResultBuilder]: At program point L197(lines 172 201) the Hoare annotation is: true [2021-12-17 15:09:12,870 INFO L858 garLoopResultBuilder]: For program point L258-2(lines 258 265) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L568(lines 563 571) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,871 INFO L861 garLoopResultBuilder]: At program point L242(lines 235 244) the Hoare annotation is: true [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L560(lines 556 562) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,871 INFO L861 garLoopResultBuilder]: At program point L267(lines 248 270) the Hoare annotation is: true [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L519(lines 519 523) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L519-2(lines 513 524) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~0#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L503(lines 503 509) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L503-1(lines 503 509) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L861 garLoopResultBuilder]: At program point L532(lines 473 536) the Hoare annotation is: true [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L495(line 495) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~0#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L553(lines 549 555) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L231(lines 227 233) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_main_~tmp~0#1|) (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L529(lines 482 530) the Hoare annotation is: false [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L484(lines 483 528) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L858 garLoopResultBuilder]: For program point L513(lines 513 524) no Hoare annotation was computed. [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L505(line 505) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~0#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,871 INFO L854 garLoopResultBuilder]: At program point L526(lines 483 528) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~0#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,872 INFO L858 garLoopResultBuilder]: For program point L493(lines 493 499) no Hoare annotation was computed. [2021-12-17 15:09:12,872 INFO L858 garLoopResultBuilder]: For program point L493-1(lines 493 499) no Hoare annotation was computed. [2021-12-17 15:09:12,872 INFO L858 garLoopResultBuilder]: For program point L485(lines 485 489) no Hoare annotation was computed. [2021-12-17 15:09:12,872 INFO L858 garLoopResultBuilder]: For program point L258(lines 258 265) no Hoare annotation was computed. [2021-12-17 15:09:12,872 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 311 335) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,872 INFO L854 garLoopResultBuilder]: At program point L155(lines 146 159) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse0 (= ~pumpRunning~0 0))) (and (or (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0) (not (= ~waterLevel~0 1)) .cse1 .cse2) (or .cse1 .cse2 (not (<= 2 ~waterLevel~0)) .cse0))) [2021-12-17 15:09:12,872 INFO L854 garLoopResultBuilder]: At program point L325(line 325) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0) (= ~pumpRunning~0 0))) [2021-12-17 15:09:12,872 INFO L854 garLoopResultBuilder]: At program point L449(lines 434 452) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= ~waterLevel~0 1)) (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) .cse0) .cse1 .cse2) (or .cse1 .cse2 (not (<= 2 ~waterLevel~0)) .cse0))) [2021-12-17 15:09:12,872 INFO L858 garLoopResultBuilder]: For program point L319(lines 319 327) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 311 335) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L315(lines 315 332) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L443(lines 443 447) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L443-2(lines 443 447) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L150(lines 150 156) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L854 garLoopResultBuilder]: At program point L367(lines 362 369) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (<= 2 ~waterLevel~0) (not (= ~systemActive~0 1))) [2021-12-17 15:09:12,873 INFO L854 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1))) [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L330-1(lines 311 335) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 81 92) no Hoare annotation was computed. [2021-12-17 15:09:12,873 INFO L858 garLoopResultBuilder]: For program point L85-1(lines 81 92) no Hoare annotation was computed. [2021-12-17 15:09:12,874 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 81 92) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1))) [2021-12-17 15:09:12,877 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:12,877 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:09:12,899 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:09:12 BoogieIcfgContainer [2021-12-17 15:09:12,899 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:09:12,899 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:09:12,900 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:09:12,900 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:09:12,900 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06" (3/4) ... [2021-12-17 15:09:12,917 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:09:12,923 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:09:12,923 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:09:12,923 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:09:12,923 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:09:12,924 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:12,924 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:09:12,933 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 53 nodes and edges [2021-12-17 15:09:12,933 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:09:12,934 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:09:12,934 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:09:12,934 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:09:12,934 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:12,935 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:12,950 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((systemActive == \result && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:09:12,950 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((systemActive == tmp && systemActive == \result) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:09:12,950 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 2 <= waterLevel) && systemActive == 1) || (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) [2021-12-17 15:09:12,951 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) [2021-12-17 15:09:12,952 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == \old(waterLevel) && 2 <= waterLevel) || !(2 <= \old(waterLevel))) || ((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) && (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((2 <= \result && waterLevel == \old(waterLevel)) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && \old(waterLevel) < 2) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && 1 <= \result) && pumpRunning == 0)) || ((2 <= \result && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(systemActive == 1))) && (((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && \old(waterLevel) < 2) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || ((((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && 1 <= tmp) && 1 <= \result) && pumpRunning == 0)) || (((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(systemActive == 1))) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1)) || !(systemActive == 1)) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((1 <= \result && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1) && tmp == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,953 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) [2021-12-17 15:09:12,954 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,954 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,954 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) [2021-12-17 15:09:12,978 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:09:12,978 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:09:12,978 INFO L158 Benchmark]: Toolchain (without parser) took 7600.25ms. Allocated memory was 79.7MB in the beginning and 161.5MB in the end (delta: 81.8MB). Free memory was 40.9MB in the beginning and 129.0MB in the end (delta: -88.1MB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:09:12,979 INFO L158 Benchmark]: CDTParser took 0.21ms. Allocated memory is still 79.7MB. Free memory was 58.7MB in the beginning and 58.7MB in the end (delta: 40.1kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:09:12,979 INFO L158 Benchmark]: CACSL2BoogieTranslator took 364.75ms. Allocated memory was 79.7MB in the beginning and 104.9MB in the end (delta: 25.2MB). Free memory was 40.7MB in the beginning and 73.7MB in the end (delta: -33.0MB). Peak memory consumption was 10.8MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,979 INFO L158 Benchmark]: Boogie Procedure Inliner took 60.73ms. Allocated memory is still 104.9MB. Free memory was 73.7MB in the beginning and 71.1MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,979 INFO L158 Benchmark]: Boogie Preprocessor took 17.01ms. Allocated memory is still 104.9MB. Free memory was 71.1MB in the beginning and 69.6MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,980 INFO L158 Benchmark]: RCFGBuilder took 358.40ms. Allocated memory is still 104.9MB. Free memory was 69.6MB in the beginning and 53.6MB in the end (delta: 16.0MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,980 INFO L158 Benchmark]: TraceAbstraction took 6715.01ms. Allocated memory was 104.9MB in the beginning and 161.5MB in the end (delta: 56.6MB). Free memory was 53.4MB in the beginning and 135.4MB in the end (delta: -82.0MB). Peak memory consumption was 72.5MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,980 INFO L158 Benchmark]: Witness Printer took 78.57ms. Allocated memory is still 161.5MB. Free memory was 135.4MB in the beginning and 129.0MB in the end (delta: 6.4MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,981 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.21ms. Allocated memory is still 79.7MB. Free memory was 58.7MB in the beginning and 58.7MB in the end (delta: 40.1kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 364.75ms. Allocated memory was 79.7MB in the beginning and 104.9MB in the end (delta: 25.2MB). Free memory was 40.7MB in the beginning and 73.7MB in the end (delta: -33.0MB). Peak memory consumption was 10.8MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 60.73ms. Allocated memory is still 104.9MB. Free memory was 73.7MB in the beginning and 71.1MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 17.01ms. Allocated memory is still 104.9MB. Free memory was 71.1MB in the beginning and 69.6MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 358.40ms. Allocated memory is still 104.9MB. Free memory was 69.6MB in the beginning and 53.6MB in the end (delta: 16.0MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. * TraceAbstraction took 6715.01ms. Allocated memory was 104.9MB in the beginning and 161.5MB in the end (delta: 56.6MB). Free memory was 53.4MB in the beginning and 135.4MB in the end (delta: -82.0MB). Peak memory consumption was 72.5MB. Max. memory is 16.1GB. * Witness Printer took 78.57ms. Allocated memory is still 161.5MB. Free memory was 135.4MB in the beginning and 129.0MB in the end (delta: 6.4MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 82 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 6.6s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.9s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.1s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2101 SdHoareTripleChecker+Valid, 1.6s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2072 mSDsluCounter, 5192 SdHoareTripleChecker+Invalid, 1.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3884 mSDsCounter, 552 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3052 IncrementalHoareTripleChecker+Invalid, 3604 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 552 mSolverCounterUnsat, 1308 mSDtfsCounter, 3052 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 581 GetRequests, 425 SyntacticMatches, 4 SemanticMatches, 152 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1007 ImplicationChecksByTransitivity, 1.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=525occurred in iteration=11, InterpolantAutomatonStates: 142, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 205 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 977 PreInvPairs, 1057 NumberOfFragments, 949 HoareAnnotationTreeSize, 977 FomulaSimplifications, 420 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 38 FomulaSimplificationsInter, 2682 FormulaSimplificationTreeSizeReductionInter, 0.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 747 NumberOfCodeBlocks, 747 NumberOfCodeBlocksAsserted, 14 NumberOfCheckSat, 903 ConstructedInterpolants, 0 QuantifiedInterpolants, 1703 SizeOfPredicates, 7 NumberOfNonLiveVariables, 898 ConjunctsInSsa, 19 ConjunctsInUnsatCore, 16 InterpolantComputations, 10 PerfectInterpolantSequences, 279/308 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 337]: Loop Invariant Derived loop invariant: ((((waterLevel == \old(waterLevel) && 2 <= waterLevel) || !(2 <= \old(waterLevel))) || ((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) && (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 453]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1) && tmp == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 556]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 362]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) - InvariantResult [Line: 482]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 172]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 473]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: (((((((2 <= \result && waterLevel == \old(waterLevel)) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && \old(waterLevel) < 2) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && 1 <= \result) && pumpRunning == 0)) || ((2 <= \result && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(systemActive == 1))) && (((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 248]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 69]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) - InvariantResult [Line: 389]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 434]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) - InvariantResult [Line: 483]: Loop Invariant Derived loop invariant: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 2 <= waterLevel) && systemActive == 1) || (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 227]: Loop Invariant Derived loop invariant: (((systemActive == tmp && systemActive == \result) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 160]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 235]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 573]: Loop Invariant Derived loop invariant: ((((((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && \old(waterLevel) < 2) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || ((((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && 1 <= tmp) && 1 <= \result) && pumpRunning == 0)) || (((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(systemActive == 1))) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1)) || !(systemActive == 1)) - InvariantResult [Line: 563]: Loop Invariant Derived loop invariant: ((systemActive == \result && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 370]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= \result) && 1 <= tmp) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 146]: Loop Invariant Derived loop invariant: ((((1 <= \result && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) RESULT: Ultimate proved your program to be correct! [2021-12-17 15:09:13,030 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE