./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash d44823aac48cec2911f68e219166f3ac1836e56b97e3a905bce4580d699376f2 --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:09:04,849 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:09:04,851 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:09:04,894 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:09:04,902 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:09:04,904 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:09:04,906 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:09:04,909 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:09:04,911 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:09:04,917 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:09:04,918 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:09:04,919 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:09:04,920 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:09:04,922 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:09:04,923 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:09:04,925 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:09:04,926 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:09:04,930 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:09:04,931 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:09:04,936 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:09:04,936 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:09:04,939 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:09:04,940 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:09:04,940 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:09:04,942 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:09:04,951 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:09:04,951 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:09:04,952 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:09:04,952 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:09:04,953 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:09:04,953 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:09:04,953 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:09:04,954 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:09:04,954 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:09:04,955 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:09:04,955 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:09:04,955 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:09:04,955 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:09:04,955 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:09:04,956 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:09:04,956 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:09:04,967 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:09:04,994 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:09:04,995 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:09:04,995 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:09:04,995 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:09:04,995 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:09:04,995 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:09:04,996 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:09:04,996 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:09:04,996 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:09:04,997 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:04,997 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:09:04,997 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:09:04,998 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> d44823aac48cec2911f68e219166f3ac1836e56b97e3a905bce4580d699376f2 [2021-12-17 15:09:05,173 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:09:05,191 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:09:05,192 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:09:05,194 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:09:05,195 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:09:05,196 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c [2021-12-17 15:09:05,236 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4131e9ffc/a20cfdcaca0c446fb2409560c133cc18/FLAG0bb5c98a1 [2021-12-17 15:09:05,682 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:09:05,684 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c [2021-12-17 15:09:05,694 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4131e9ffc/a20cfdcaca0c446fb2409560c133cc18/FLAG0bb5c98a1 [2021-12-17 15:09:05,711 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4131e9ffc/a20cfdcaca0c446fb2409560c133cc18 [2021-12-17 15:09:05,714 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:09:05,715 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:09:05,716 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:05,716 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:09:05,719 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:09:05,719 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,720 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@57755209 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:05, skipping insertion in model container [2021-12-17 15:09:05,720 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:05" (1/1) ... [2021-12-17 15:09:05,725 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:09:05,768 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:09:06,085 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c[13010,13023] [2021-12-17 15:09:06,175 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:06,181 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:09:06,207 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product50.cil.c[13010,13023] [2021-12-17 15:09:06,217 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:06,228 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:09:06,228 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06 WrapperNode [2021-12-17 15:09:06,229 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:06,230 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:06,230 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:09:06,230 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:09:06,235 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,257 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,282 INFO L137 Inliner]: procedures = 56, calls = 155, calls flagged for inlining = 25, calls inlined = 21, statements flattened = 260 [2021-12-17 15:09:06,283 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:06,283 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:09:06,283 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:09:06,283 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:09:06,293 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,293 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,296 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,296 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,308 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,323 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,325 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,326 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:09:06,327 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:09:06,327 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:09:06,327 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:09:06,328 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (1/1) ... [2021-12-17 15:09:06,341 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:06,350 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:06,361 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:09:06,363 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:09:06,393 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:09:06,394 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:09:06,394 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:09:06,394 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:09:06,394 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:09:06,394 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:09:06,395 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:09:06,396 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:06,396 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:06,396 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:09:06,396 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:09:06,396 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:09:06,396 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:09:06,397 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:09:06,397 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:09:06,397 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:09:06,477 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:09:06,492 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:09:06,737 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:09:06,744 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:09:06,744 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:09:06,745 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06 BoogieIcfgContainer [2021-12-17 15:09:06,746 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:09:06,748 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:09:06,748 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:09:06,751 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:09:06,751 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:09:05" (1/3) ... [2021-12-17 15:09:06,752 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@37c26a49 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:06, skipping insertion in model container [2021-12-17 15:09:06,752 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:06" (2/3) ... [2021-12-17 15:09:06,753 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@37c26a49 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:06, skipping insertion in model container [2021-12-17 15:09:06,753 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06" (3/3) ... [2021-12-17 15:09:06,754 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product50.cil.c [2021-12-17 15:09:06,758 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:09:06,759 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:09:06,801 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:09:06,807 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:09:06,808 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:09:06,831 INFO L276 IsEmpty]: Start isEmpty. Operand has 83 states, 65 states have (on average 1.4) internal successors, (91), 73 states have internal predecessors, (91), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-17 15:09:06,836 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2021-12-17 15:09:06,836 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:06,837 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:06,838 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:06,842 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:06,842 INFO L85 PathProgramCache]: Analyzing trace with hash -340967460, now seen corresponding path program 1 times [2021-12-17 15:09:06,849 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:06,849 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1776722842] [2021-12-17 15:09:06,849 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:06,850 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:06,969 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,039 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,040 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,040 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1776722842] [2021-12-17 15:09:07,065 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1776722842] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,066 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,066 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:07,068 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [133880762] [2021-12-17 15:09:07,068 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,072 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:09:07,073 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,095 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:09:07,096 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:07,098 INFO L87 Difference]: Start difference. First operand has 83 states, 65 states have (on average 1.4) internal successors, (91), 73 states have internal predecessors, (91), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,133 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,134 INFO L93 Difference]: Finished difference Result 158 states and 217 transitions. [2021-12-17 15:09:07,134 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:09:07,135 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2021-12-17 15:09:07,136 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,145 INFO L225 Difference]: With dead ends: 158 [2021-12-17 15:09:07,145 INFO L226 Difference]: Without dead ends: 74 [2021-12-17 15:09:07,149 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:07,152 INFO L933 BasicCegarLoop]: 105 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 105 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,153 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 105 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:07,163 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 74 states. [2021-12-17 15:09:07,183 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 74 to 74. [2021-12-17 15:09:07,184 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 74 states, 58 states have (on average 1.3275862068965518) internal successors, (77), 65 states have internal predecessors, (77), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-17 15:09:07,187 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 74 states to 74 states and 96 transitions. [2021-12-17 15:09:07,189 INFO L78 Accepts]: Start accepts. Automaton has 74 states and 96 transitions. Word has length 19 [2021-12-17 15:09:07,189 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,189 INFO L470 AbstractCegarLoop]: Abstraction has 74 states and 96 transitions. [2021-12-17 15:09:07,190 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,190 INFO L276 IsEmpty]: Start isEmpty. Operand 74 states and 96 transitions. [2021-12-17 15:09:07,193 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2021-12-17 15:09:07,193 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,194 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,194 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:09:07,195 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,195 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,196 INFO L85 PathProgramCache]: Analyzing trace with hash -1018100204, now seen corresponding path program 1 times [2021-12-17 15:09:07,196 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,196 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1420764735] [2021-12-17 15:09:07,196 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,197 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,226 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,260 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,260 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,261 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1420764735] [2021-12-17 15:09:07,261 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1420764735] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,261 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,261 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:09:07,261 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [874101333] [2021-12-17 15:09:07,261 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,263 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:07,263 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,264 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:07,264 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:07,265 INFO L87 Difference]: Start difference. First operand 74 states and 96 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,292 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,292 INFO L93 Difference]: Finished difference Result 113 states and 147 transitions. [2021-12-17 15:09:07,294 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:07,294 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2021-12-17 15:09:07,295 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,296 INFO L225 Difference]: With dead ends: 113 [2021-12-17 15:09:07,296 INFO L226 Difference]: Without dead ends: 65 [2021-12-17 15:09:07,297 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:07,298 INFO L933 BasicCegarLoop]: 83 mSDtfsCounter, 13 mSDsluCounter, 66 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 149 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,300 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 149 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:07,301 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 65 states. [2021-12-17 15:09:07,306 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 65 to 65. [2021-12-17 15:09:07,308 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 65 states, 52 states have (on average 1.3461538461538463) internal successors, (70), 59 states have internal predecessors, (70), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-17 15:09:07,308 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 65 states to 65 states and 84 transitions. [2021-12-17 15:09:07,309 INFO L78 Accepts]: Start accepts. Automaton has 65 states and 84 transitions. Word has length 20 [2021-12-17 15:09:07,309 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,309 INFO L470 AbstractCegarLoop]: Abstraction has 65 states and 84 transitions. [2021-12-17 15:09:07,310 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,310 INFO L276 IsEmpty]: Start isEmpty. Operand 65 states and 84 transitions. [2021-12-17 15:09:07,313 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-17 15:09:07,314 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,314 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,314 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:09:07,314 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,315 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,315 INFO L85 PathProgramCache]: Analyzing trace with hash -2024480710, now seen corresponding path program 1 times [2021-12-17 15:09:07,316 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,316 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [90602816] [2021-12-17 15:09:07,316 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,317 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,336 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,365 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,365 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,365 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [90602816] [2021-12-17 15:09:07,365 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [90602816] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,366 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,366 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:07,366 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1097063884] [2021-12-17 15:09:07,366 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,367 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:07,367 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,368 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:07,368 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:07,369 INFO L87 Difference]: Start difference. First operand 65 states and 84 transitions. Second operand has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,386 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,387 INFO L93 Difference]: Finished difference Result 123 states and 162 transitions. [2021-12-17 15:09:07,388 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:07,388 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2021-12-17 15:09:07,388 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,390 INFO L225 Difference]: With dead ends: 123 [2021-12-17 15:09:07,390 INFO L226 Difference]: Without dead ends: 65 [2021-12-17 15:09:07,390 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:07,392 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 64 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 64 SdHoareTripleChecker+Valid, 82 SdHoareTripleChecker+Invalid, 2 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,393 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [64 Valid, 82 Invalid, 2 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:07,393 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 65 states. [2021-12-17 15:09:07,398 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 65 to 65. [2021-12-17 15:09:07,398 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 65 states, 52 states have (on average 1.3269230769230769) internal successors, (69), 59 states have internal predecessors, (69), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-17 15:09:07,398 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 65 states to 65 states and 83 transitions. [2021-12-17 15:09:07,399 INFO L78 Accepts]: Start accepts. Automaton has 65 states and 83 transitions. Word has length 25 [2021-12-17 15:09:07,399 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,399 INFO L470 AbstractCegarLoop]: Abstraction has 65 states and 83 transitions. [2021-12-17 15:09:07,399 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:07,399 INFO L276 IsEmpty]: Start isEmpty. Operand 65 states and 83 transitions. [2021-12-17 15:09:07,400 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2021-12-17 15:09:07,400 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,401 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,401 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:09:07,401 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,402 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,402 INFO L85 PathProgramCache]: Analyzing trace with hash 1530438702, now seen corresponding path program 1 times [2021-12-17 15:09:07,402 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,402 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [229316812] [2021-12-17 15:09:07,402 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,402 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,411 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,442 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:07,446 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,475 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:07,477 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,479 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,480 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,480 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [229316812] [2021-12-17 15:09:07,480 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [229316812] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,480 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,480 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:07,480 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [841492563] [2021-12-17 15:09:07,480 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,481 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:07,481 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,481 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:07,481 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:07,481 INFO L87 Difference]: Start difference. First operand 65 states and 83 transitions. Second operand has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,625 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,626 INFO L93 Difference]: Finished difference Result 186 states and 238 transitions. [2021-12-17 15:09:07,626 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:07,626 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 35 [2021-12-17 15:09:07,626 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,627 INFO L225 Difference]: With dead ends: 186 [2021-12-17 15:09:07,627 INFO L226 Difference]: Without dead ends: 128 [2021-12-17 15:09:07,628 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:07,629 INFO L933 BasicCegarLoop]: 112 mSDtfsCounter, 149 mSDsluCounter, 159 mSDsCounter, 0 mSdLazyCounter, 72 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 151 SdHoareTripleChecker+Valid, 271 SdHoareTripleChecker+Invalid, 103 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 72 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,629 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [151 Valid, 271 Invalid, 103 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 72 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,630 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 128 states. [2021-12-17 15:09:07,643 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 128 to 122. [2021-12-17 15:09:07,643 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 122 states, 98 states have (on average 1.2755102040816326) internal successors, (125), 105 states have internal predecessors, (125), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2021-12-17 15:09:07,644 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 122 states to 122 states and 150 transitions. [2021-12-17 15:09:07,644 INFO L78 Accepts]: Start accepts. Automaton has 122 states and 150 transitions. Word has length 35 [2021-12-17 15:09:07,644 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,644 INFO L470 AbstractCegarLoop]: Abstraction has 122 states and 150 transitions. [2021-12-17 15:09:07,645 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:07,645 INFO L276 IsEmpty]: Start isEmpty. Operand 122 states and 150 transitions. [2021-12-17 15:09:07,645 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2021-12-17 15:09:07,645 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,646 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,646 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:09:07,646 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,646 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,646 INFO L85 PathProgramCache]: Analyzing trace with hash 699766483, now seen corresponding path program 1 times [2021-12-17 15:09:07,646 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,647 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1206699302] [2021-12-17 15:09:07,647 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,647 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,680 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:07,682 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,698 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,698 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,698 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1206699302] [2021-12-17 15:09:07,698 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1206699302] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,698 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,699 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:07,699 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [537947956] [2021-12-17 15:09:07,699 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,699 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:07,699 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,700 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:07,700 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:07,700 INFO L87 Difference]: Start difference. First operand 122 states and 150 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,866 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:07,866 INFO L93 Difference]: Finished difference Result 346 states and 449 transitions. [2021-12-17 15:09:07,866 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-17 15:09:07,867 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 39 [2021-12-17 15:09:07,867 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:07,868 INFO L225 Difference]: With dead ends: 346 [2021-12-17 15:09:07,869 INFO L226 Difference]: Without dead ends: 231 [2021-12-17 15:09:07,870 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 19 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=111, Unknown=0, NotChecked=0, Total=156 [2021-12-17 15:09:07,870 INFO L933 BasicCegarLoop]: 100 mSDtfsCounter, 144 mSDsluCounter, 269 mSDsCounter, 0 mSdLazyCounter, 130 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 147 SdHoareTripleChecker+Valid, 369 SdHoareTripleChecker+Invalid, 166 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 130 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:07,871 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [147 Valid, 369 Invalid, 166 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 130 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:07,871 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 231 states. [2021-12-17 15:09:07,886 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 231 to 198. [2021-12-17 15:09:07,887 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 198 states, 159 states have (on average 1.2767295597484276) internal successors, (203), 168 states have internal predecessors, (203), 18 states have call successors, (18), 18 states have call predecessors, (18), 20 states have return successors, (28), 18 states have call predecessors, (28), 18 states have call successors, (28) [2021-12-17 15:09:07,888 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 249 transitions. [2021-12-17 15:09:07,888 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 249 transitions. Word has length 39 [2021-12-17 15:09:07,888 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:07,888 INFO L470 AbstractCegarLoop]: Abstraction has 198 states and 249 transitions. [2021-12-17 15:09:07,888 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:07,889 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 249 transitions. [2021-12-17 15:09:07,889 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2021-12-17 15:09:07,890 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:07,890 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:07,890 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:09:07,890 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:07,890 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:07,891 INFO L85 PathProgramCache]: Analyzing trace with hash 1720834837, now seen corresponding path program 1 times [2021-12-17 15:09:07,891 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:07,891 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [841574860] [2021-12-17 15:09:07,891 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:07,891 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:07,901 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,915 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:07,918 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:07,936 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:07,936 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:07,937 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [841574860] [2021-12-17 15:09:07,937 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [841574860] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:07,937 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:07,937 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:07,937 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1661593739] [2021-12-17 15:09:07,937 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:07,938 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:07,938 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:07,938 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:07,938 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:07,938 INFO L87 Difference]: Start difference. First operand 198 states and 249 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:08,025 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:08,025 INFO L93 Difference]: Finished difference Result 403 states and 514 transitions. [2021-12-17 15:09:08,025 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:08,026 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 39 [2021-12-17 15:09:08,026 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:08,027 INFO L225 Difference]: With dead ends: 403 [2021-12-17 15:09:08,027 INFO L226 Difference]: Without dead ends: 212 [2021-12-17 15:09:08,028 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:09:08,029 INFO L933 BasicCegarLoop]: 83 mSDtfsCounter, 59 mSDsluCounter, 261 mSDsCounter, 0 mSdLazyCounter, 84 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 60 SdHoareTripleChecker+Valid, 344 SdHoareTripleChecker+Invalid, 101 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 84 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:08,029 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [60 Valid, 344 Invalid, 101 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 84 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:08,030 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 212 states. [2021-12-17 15:09:08,041 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 212 to 204. [2021-12-17 15:09:08,042 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 204 states, 165 states have (on average 1.2666666666666666) internal successors, (209), 174 states have internal predecessors, (209), 18 states have call successors, (18), 18 states have call predecessors, (18), 20 states have return successors, (28), 18 states have call predecessors, (28), 18 states have call successors, (28) [2021-12-17 15:09:08,043 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 204 states to 204 states and 255 transitions. [2021-12-17 15:09:08,043 INFO L78 Accepts]: Start accepts. Automaton has 204 states and 255 transitions. Word has length 39 [2021-12-17 15:09:08,043 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:08,044 INFO L470 AbstractCegarLoop]: Abstraction has 204 states and 255 transitions. [2021-12-17 15:09:08,044 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:08,044 INFO L276 IsEmpty]: Start isEmpty. Operand 204 states and 255 transitions. [2021-12-17 15:09:08,045 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2021-12-17 15:09:08,045 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:08,045 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:08,045 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:09:08,046 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:08,046 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:08,046 INFO L85 PathProgramCache]: Analyzing trace with hash 709717587, now seen corresponding path program 1 times [2021-12-17 15:09:08,046 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:08,046 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1603242821] [2021-12-17 15:09:08,046 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,047 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:08,064 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,076 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:08,078 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,090 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:08,091 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:08,091 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1603242821] [2021-12-17 15:09:08,091 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1603242821] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:08,091 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:08,091 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:08,091 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [687165297] [2021-12-17 15:09:08,092 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:08,092 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:08,092 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:08,092 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:08,093 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:08,093 INFO L87 Difference]: Start difference. First operand 204 states and 255 transitions. Second operand has 5 states, 5 states have (on average 7.2) internal successors, (36), 4 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:08,156 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:08,157 INFO L93 Difference]: Finished difference Result 372 states and 470 transitions. [2021-12-17 15:09:08,157 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:09:08,157 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.2) internal successors, (36), 4 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 39 [2021-12-17 15:09:08,158 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:08,159 INFO L225 Difference]: With dead ends: 372 [2021-12-17 15:09:08,159 INFO L226 Difference]: Without dead ends: 175 [2021-12-17 15:09:08,159 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:08,160 INFO L933 BasicCegarLoop]: 70 mSDtfsCounter, 60 mSDsluCounter, 158 mSDsCounter, 0 mSdLazyCounter, 62 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 62 SdHoareTripleChecker+Valid, 228 SdHoareTripleChecker+Invalid, 75 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 62 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:08,160 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [62 Valid, 228 Invalid, 75 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 62 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:08,161 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2021-12-17 15:09:08,168 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 170. [2021-12-17 15:09:08,169 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 170 states, 137 states have (on average 1.2408759124087592) internal successors, (170), 145 states have internal predecessors, (170), 15 states have call successors, (15), 15 states have call predecessors, (15), 17 states have return successors, (20), 15 states have call predecessors, (20), 15 states have call successors, (20) [2021-12-17 15:09:08,169 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 170 states to 170 states and 205 transitions. [2021-12-17 15:09:08,170 INFO L78 Accepts]: Start accepts. Automaton has 170 states and 205 transitions. Word has length 39 [2021-12-17 15:09:08,170 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:08,170 INFO L470 AbstractCegarLoop]: Abstraction has 170 states and 205 transitions. [2021-12-17 15:09:08,170 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.2) internal successors, (36), 4 states have internal predecessors, (36), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:08,170 INFO L276 IsEmpty]: Start isEmpty. Operand 170 states and 205 transitions. [2021-12-17 15:09:08,171 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-17 15:09:08,171 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:08,171 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:08,172 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:09:08,172 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:08,172 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:08,172 INFO L85 PathProgramCache]: Analyzing trace with hash 11284582, now seen corresponding path program 1 times [2021-12-17 15:09:08,172 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:08,173 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1603931516] [2021-12-17 15:09:08,173 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,173 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:08,181 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,211 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:08,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,216 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:08,217 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,219 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:08,219 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:08,219 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1603931516] [2021-12-17 15:09:08,219 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1603931516] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:08,219 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:08,219 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:08,220 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [126636190] [2021-12-17 15:09:08,220 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:08,220 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:08,220 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:08,220 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:08,221 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:08,221 INFO L87 Difference]: Start difference. First operand 170 states and 205 transitions. Second operand has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 6 states have internal predecessors, (36), 3 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:08,421 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:08,421 INFO L93 Difference]: Finished difference Result 475 states and 597 transitions. [2021-12-17 15:09:08,422 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-17 15:09:08,422 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 6 states have internal predecessors, (36), 3 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2021-12-17 15:09:08,422 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:08,423 INFO L225 Difference]: With dead ends: 475 [2021-12-17 15:09:08,424 INFO L226 Difference]: Without dead ends: 312 [2021-12-17 15:09:08,424 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 37 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=85, Invalid=187, Unknown=0, NotChecked=0, Total=272 [2021-12-17 15:09:08,425 INFO L933 BasicCegarLoop]: 84 mSDtfsCounter, 239 mSDsluCounter, 303 mSDsCounter, 0 mSdLazyCounter, 191 mSolverCounterSat, 59 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 242 SdHoareTripleChecker+Valid, 387 SdHoareTripleChecker+Invalid, 250 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 59 IncrementalHoareTripleChecker+Valid, 191 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:08,425 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [242 Valid, 387 Invalid, 250 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [59 Valid, 191 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:08,426 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 312 states. [2021-12-17 15:09:08,436 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 312 to 257. [2021-12-17 15:09:08,437 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 257 states, 205 states have (on average 1.2146341463414634) internal successors, (249), 218 states have internal predecessors, (249), 23 states have call successors, (23), 23 states have call predecessors, (23), 28 states have return successors, (40), 25 states have call predecessors, (40), 23 states have call successors, (40) [2021-12-17 15:09:08,438 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 257 states to 257 states and 312 transitions. [2021-12-17 15:09:08,438 INFO L78 Accepts]: Start accepts. Automaton has 257 states and 312 transitions. Word has length 41 [2021-12-17 15:09:08,438 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:08,439 INFO L470 AbstractCegarLoop]: Abstraction has 257 states and 312 transitions. [2021-12-17 15:09:08,439 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 6 states have internal predecessors, (36), 3 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:08,439 INFO L276 IsEmpty]: Start isEmpty. Operand 257 states and 312 transitions. [2021-12-17 15:09:08,440 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2021-12-17 15:09:08,440 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:08,440 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:08,440 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:09:08,440 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:08,441 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:08,441 INFO L85 PathProgramCache]: Analyzing trace with hash -422364352, now seen corresponding path program 1 times [2021-12-17 15:09:08,441 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:08,441 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [50583929] [2021-12-17 15:09:08,441 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,441 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:08,449 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,476 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:08,477 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,483 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:09:08,485 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,489 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:08,490 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,492 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:08,492 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:08,492 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [50583929] [2021-12-17 15:09:08,492 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [50583929] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:08,492 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:08,492 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:08,493 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [793223269] [2021-12-17 15:09:08,493 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:08,493 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:08,493 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:08,493 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:08,494 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:08,494 INFO L87 Difference]: Start difference. First operand 257 states and 312 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:08,708 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:08,709 INFO L93 Difference]: Finished difference Result 304 states and 367 transitions. [2021-12-17 15:09:08,709 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2021-12-17 15:09:08,709 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) Word has length 45 [2021-12-17 15:09:08,710 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:08,711 INFO L225 Difference]: With dead ends: 304 [2021-12-17 15:09:08,711 INFO L226 Difference]: Without dead ends: 302 [2021-12-17 15:09:08,711 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 60 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=99, Invalid=243, Unknown=0, NotChecked=0, Total=342 [2021-12-17 15:09:08,712 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 172 mSDsluCounter, 301 mSDsCounter, 0 mSdLazyCounter, 216 mSolverCounterSat, 38 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 173 SdHoareTripleChecker+Valid, 390 SdHoareTripleChecker+Invalid, 254 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 38 IncrementalHoareTripleChecker+Valid, 216 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:08,712 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [173 Valid, 390 Invalid, 254 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [38 Valid, 216 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:08,713 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 302 states. [2021-12-17 15:09:08,723 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 302 to 285. [2021-12-17 15:09:08,723 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 230 states have (on average 1.2043478260869565) internal successors, (277), 245 states have internal predecessors, (277), 24 states have call successors, (24), 23 states have call predecessors, (24), 30 states have return successors, (43), 26 states have call predecessors, (43), 24 states have call successors, (43) [2021-12-17 15:09:08,725 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 344 transitions. [2021-12-17 15:09:08,725 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 344 transitions. Word has length 45 [2021-12-17 15:09:08,725 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:08,725 INFO L470 AbstractCegarLoop]: Abstraction has 285 states and 344 transitions. [2021-12-17 15:09:08,725 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:08,726 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 344 transitions. [2021-12-17 15:09:08,727 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 79 [2021-12-17 15:09:08,727 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:08,727 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:08,727 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:09:08,727 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:08,728 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:08,728 INFO L85 PathProgramCache]: Analyzing trace with hash 1050725005, now seen corresponding path program 1 times [2021-12-17 15:09:08,728 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:08,728 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [177895293] [2021-12-17 15:09:08,728 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,728 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:08,741 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:08,776 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:08,786 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:08,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2021-12-17 15:09:08,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,805 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:08,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,807 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 12 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-12-17 15:09:08,807 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:08,807 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [177895293] [2021-12-17 15:09:08,808 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [177895293] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:08,808 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [642875040] [2021-12-17 15:09:08,808 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:08,808 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:08,808 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:08,809 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:08,810 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:09:08,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:08,899 INFO L263 TraceCheckSpWp]: Trace formula consists of 431 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-17 15:09:08,903 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:09,060 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:09,060 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:09:09,211 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-12-17 15:09:09,211 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [642875040] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:09:09,212 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:09:09,212 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 11 [2021-12-17 15:09:09,212 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1443942263] [2021-12-17 15:09:09,212 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:09:09,212 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 11 states [2021-12-17 15:09:09,213 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:09,213 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 11 interpolants. [2021-12-17 15:09:09,213 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=86, Unknown=0, NotChecked=0, Total=110 [2021-12-17 15:09:09,213 INFO L87 Difference]: Start difference. First operand 285 states and 344 transitions. Second operand has 11 states, 11 states have (on average 6.909090909090909) internal successors, (76), 8 states have internal predecessors, (76), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2021-12-17 15:09:09,646 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:09,646 INFO L93 Difference]: Finished difference Result 633 states and 817 transitions. [2021-12-17 15:09:09,647 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 26 states. [2021-12-17 15:09:09,647 INFO L78 Accepts]: Start accepts. Automaton has has 11 states, 11 states have (on average 6.909090909090909) internal successors, (76), 8 states have internal predecessors, (76), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 78 [2021-12-17 15:09:09,647 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:09,649 INFO L225 Difference]: With dead ends: 633 [2021-12-17 15:09:09,649 INFO L226 Difference]: Without dead ends: 396 [2021-12-17 15:09:09,650 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 195 GetRequests, 165 SyntacticMatches, 3 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 185 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=208, Invalid=604, Unknown=0, NotChecked=0, Total=812 [2021-12-17 15:09:09,651 INFO L933 BasicCegarLoop]: 121 mSDtfsCounter, 312 mSDsluCounter, 587 mSDsCounter, 0 mSdLazyCounter, 489 mSolverCounterSat, 88 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 316 SdHoareTripleChecker+Valid, 708 SdHoareTripleChecker+Invalid, 577 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 88 IncrementalHoareTripleChecker+Valid, 489 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:09,651 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [316 Valid, 708 Invalid, 577 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [88 Valid, 489 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:09:09,652 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 396 states. [2021-12-17 15:09:09,663 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 396 to 348. [2021-12-17 15:09:09,664 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 348 states, 276 states have (on average 1.213768115942029) internal successors, (335), 294 states have internal predecessors, (335), 34 states have call successors, (34), 33 states have call predecessors, (34), 37 states have return successors, (61), 32 states have call predecessors, (61), 34 states have call successors, (61) [2021-12-17 15:09:09,666 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 348 states to 348 states and 430 transitions. [2021-12-17 15:09:09,666 INFO L78 Accepts]: Start accepts. Automaton has 348 states and 430 transitions. Word has length 78 [2021-12-17 15:09:09,668 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:09,669 INFO L470 AbstractCegarLoop]: Abstraction has 348 states and 430 transitions. [2021-12-17 15:09:09,669 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 11 states, 11 states have (on average 6.909090909090909) internal successors, (76), 8 states have internal predecessors, (76), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2021-12-17 15:09:09,669 INFO L276 IsEmpty]: Start isEmpty. Operand 348 states and 430 transitions. [2021-12-17 15:09:09,670 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 114 [2021-12-17 15:09:09,670 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:09,670 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:09,688 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:09:09,888 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-17 15:09:09,888 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:09,889 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:09,889 INFO L85 PathProgramCache]: Analyzing trace with hash 1937588267, now seen corresponding path program 2 times [2021-12-17 15:09:09,889 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:09,889 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2120458622] [2021-12-17 15:09:09,889 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:09,889 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:09,904 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,927 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:09,928 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,933 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:09,935 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,943 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:09,945 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2021-12-17 15:09:09,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,017 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-17 15:09:10,019 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,020 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:10,021 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,022 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2021-12-17 15:09:10,023 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,024 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:10,025 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,026 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 54 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2021-12-17 15:09:10,026 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,026 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2120458622] [2021-12-17 15:09:10,026 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2120458622] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:10,026 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [948292882] [2021-12-17 15:09:10,026 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2021-12-17 15:09:10,027 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:10,027 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:10,048 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:10,049 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:09:10,125 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2021-12-17 15:09:10,126 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2021-12-17 15:09:10,128 INFO L263 TraceCheckSpWp]: Trace formula consists of 520 conjuncts, 10 conjunts are in the unsatisfiable core [2021-12-17 15:09:10,130 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:10,318 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2021-12-17 15:09:10,318 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:09:10,318 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [948292882] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,318 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:09:10,318 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2021-12-17 15:09:10,318 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2015738690] [2021-12-17 15:09:10,319 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,319 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:10,319 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,319 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:10,319 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2021-12-17 15:09:10,320 INFO L87 Difference]: Start difference. First operand 348 states and 430 transitions. Second operand has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-17 15:09:10,521 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,522 INFO L93 Difference]: Finished difference Result 927 states and 1188 transitions. [2021-12-17 15:09:10,522 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2021-12-17 15:09:10,522 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 113 [2021-12-17 15:09:10,522 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,525 INFO L225 Difference]: With dead ends: 927 [2021-12-17 15:09:10,525 INFO L226 Difference]: Without dead ends: 626 [2021-12-17 15:09:10,526 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 145 GetRequests, 125 SyntacticMatches, 3 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 42 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2021-12-17 15:09:10,527 INFO L933 BasicCegarLoop]: 135 mSDtfsCounter, 210 mSDsluCounter, 397 mSDsCounter, 0 mSdLazyCounter, 129 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 210 SdHoareTripleChecker+Valid, 532 SdHoareTripleChecker+Invalid, 150 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 129 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,527 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [210 Valid, 532 Invalid, 150 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 129 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:10,528 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 626 states. [2021-12-17 15:09:10,547 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 626 to 565. [2021-12-17 15:09:10,548 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 565 states, 450 states have (on average 1.2066666666666668) internal successors, (543), 475 states have internal predecessors, (543), 55 states have call successors, (55), 54 states have call predecessors, (55), 59 states have return successors, (96), 51 states have call predecessors, (96), 55 states have call successors, (96) [2021-12-17 15:09:10,550 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 565 states to 565 states and 694 transitions. [2021-12-17 15:09:10,551 INFO L78 Accepts]: Start accepts. Automaton has 565 states and 694 transitions. Word has length 113 [2021-12-17 15:09:10,551 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,551 INFO L470 AbstractCegarLoop]: Abstraction has 565 states and 694 transitions. [2021-12-17 15:09:10,551 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-17 15:09:10,551 INFO L276 IsEmpty]: Start isEmpty. Operand 565 states and 694 transitions. [2021-12-17 15:09:10,552 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 114 [2021-12-17 15:09:10,552 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,553 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,572 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2021-12-17 15:09:10,770 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:09:10,771 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,771 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,771 INFO L85 PathProgramCache]: Analyzing trace with hash -1481360023, now seen corresponding path program 1 times [2021-12-17 15:09:10,771 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,771 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1178900268] [2021-12-17 15:09:10,771 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,772 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,787 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:10,815 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,831 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:10,832 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:10,838 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,840 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2021-12-17 15:09:10,842 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,872 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-17 15:09:10,873 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,874 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:10,875 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,876 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2021-12-17 15:09:10,876 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,880 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:10,880 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,882 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2021-12-17 15:09:10,882 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,883 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1178900268] [2021-12-17 15:09:10,883 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1178900268] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,883 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,883 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-17 15:09:10,883 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [679829754] [2021-12-17 15:09:10,883 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,883 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:09:10,884 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,884 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:09:10,884 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:10,884 INFO L87 Difference]: Start difference. First operand 565 states and 694 transitions. Second operand has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-17 15:09:11,038 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,039 INFO L93 Difference]: Finished difference Result 773 states and 939 transitions. [2021-12-17 15:09:11,039 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:09:11,040 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 113 [2021-12-17 15:09:11,040 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,040 INFO L225 Difference]: With dead ends: 773 [2021-12-17 15:09:11,040 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:09:11,042 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:11,042 INFO L933 BasicCegarLoop]: 71 mSDtfsCounter, 132 mSDsluCounter, 217 mSDsCounter, 0 mSdLazyCounter, 151 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 134 SdHoareTripleChecker+Valid, 288 SdHoareTripleChecker+Invalid, 183 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 151 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,042 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [134 Valid, 288 Invalid, 183 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 151 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:11,043 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:09:11,043 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:09:11,043 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:11,043 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:09:11,043 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 113 [2021-12-17 15:09:11,043 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,044 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:09:11,044 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-17 15:09:11,044 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:09:11,044 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:09:11,046 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:09:11,046 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2021-12-17 15:09:11,048 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2021-12-17 15:09:12,673 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 624 635) the Hoare annotation is: true [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 624 635) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point L628-1(lines 624 635) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 894) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L854 garLoopResultBuilder]: At program point L696(lines 691 699) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point L890-2(lines 890 894) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L854 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,673 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 707 730) no Hoare annotation was computed. [2021-12-17 15:09:12,673 INFO L854 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) (and .cse0 .cse1) (not (= |old(~pumpRunning~0)| 0)) .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2))) [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L784-1(lines 765 789) the Hoare annotation is: (let ((.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~systemActive~0 1))) (let ((.cse0 (and .cse3 (<= 2 ~waterLevel~0) .cse4)) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (not .cse4))) (and (or .cse0 (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) .cse2)) (or .cse0 (and .cse3 .cse2) (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L718-1(lines 718 724) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L553(line 553) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L673(lines 668 676) the Hoare annotation is: (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (= ~systemActive~0 1))) (let ((.cse2 (= ~pumpRunning~0 0)) (.cse0 (and .cse4 (<= 2 ~waterLevel~0) .cse1 .cse5)) (.cse3 (not .cse5))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) .cse1 .cse2) .cse3) (or (and .cse4 .cse1 .cse2) (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse3 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L896(lines 881 899) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L822(lines 817 825) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L554(lines 549 556) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L773(lines 773 781) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L769(lines 769 786) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L604(lines 604 608) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L604-2(lines 600 611) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 707 730) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~waterLevel~0)| 1)) (and .cse0 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L431(lines 431 437) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point L427(lines 427 440) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2021-12-17 15:09:12,674 INFO L854 garLoopResultBuilder]: At program point L427-1(lines 419 443) the Hoare annotation is: (let ((.cse4 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|)) (.cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse7 (= ~systemActive~0 1))) (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (= ~pumpRunning~0 0)) (.cse2 (and .cse4 (= ~waterLevel~0 |old(~waterLevel~0)|) (<= 2 ~waterLevel~0) .cse5 .cse7)) (.cse3 (not .cse7))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse4 (= ~waterLevel~0 ~systemActive~0) .cse5 .cse6) .cse3) (or .cse0 (and .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) .cse5 .cse6) .cse2 .cse3)))) [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 553) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L854 garLoopResultBuilder]: At program point L803(lines 798 805) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= ~pumpRunning~0 0))))) [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 447 476) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 447 476) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L472(lines 447 476) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L468(line 468) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L461(lines 461 465) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L461-1(lines 461 465) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L458(line 458) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L457-2(lines 457 471) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L453(line 453) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L453-1(line 453) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L535(lines 535 542) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L535-2(lines 535 542) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L519(lines 512 521) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L861 garLoopResultBuilder]: At program point L544(lines 525 547) the Hoare annotation is: true [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L854 garLoopResultBuilder]: At program point L573(lines 569 575) the Hoare annotation is: (and (= ~waterLevel~0 ~systemActive~0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L957(lines 957 961) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L854 garLoopResultBuilder]: At program point L957-2(lines 949 962) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L920(lines 919 966) no Hoare annotation was computed. [2021-12-17 15:09:12,675 INFO L858 garLoopResultBuilder]: For program point L949(lines 949 962) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L941(line 941) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,676 INFO L861 garLoopResultBuilder]: At program point L970(lines 909 974) the Hoare annotation is: true [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L929(lines 929 935) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L929-1(lines 929 935) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L508(lines 504 510) the Hoare annotation is: (and (= ~waterLevel~0 ~systemActive~0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L921(lines 921 925) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L905(lines 900 907) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L967(lines 918 968) the Hoare annotation is: false [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L588(lines 583 591) the Hoare annotation is: (and (= ~waterLevel~0 ~systemActive~0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L939(lines 939 945) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L939-1(lines 939 945) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L580(lines 576 582) the Hoare annotation is: (and (= ~waterLevel~0 ~systemActive~0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L964(lines 919 966) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L931(line 931) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 739 763) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (= ~pumpRunning~0 0)) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L795(lines 790 797) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (<= 2 ~waterLevel~0) (not (= ~systemActive~0 1))) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1))) [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L686(lines 677 690) the Hoare annotation is: (let ((.cse3 (<= 2 ~waterLevel~0)) (.cse5 (= ~systemActive~0 1)) (.cse4 (= ~pumpRunning~0 0))) (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse3 .cse5 .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse5))) (and (or .cse0 .cse1 .cse2 (not .cse3)) (or .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1) .cse4) (not (<= 1 ~waterLevel~0)) .cse1 .cse2)))) [2021-12-17 15:09:12,676 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)) .cse0 .cse1) (or (not (= ~waterLevel~0 1)) .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~7#1| 1)) .cse1))) [2021-12-17 15:09:12,676 INFO L854 garLoopResultBuilder]: At program point L877(lines 862 880) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~waterLevel~0)) .cse0 .cse1 (= ~pumpRunning~0 0)) (or (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~7#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0)) (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L747(lines 747 755) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L681(lines 681 687) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L743(lines 743 760) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L871(lines 871 875) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L871-2(lines 871 875) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 612 623) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L858 garLoopResultBuilder]: For program point L616-1(lines 612 623) no Hoare annotation was computed. [2021-12-17 15:09:12,677 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 612 623) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) (not (= ~pumpRunning~0 0)) .cse0 .cse1) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1))) [2021-12-17 15:09:12,679 INFO L732 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:12,680 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:09:12,696 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:09:12 BoogieIcfgContainer [2021-12-17 15:09:12,696 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:09:12,696 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:09:12,697 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:09:12,697 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:09:12,697 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:06" (3/4) ... [2021-12-17 15:09:12,699 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:09:12,703 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:09:12,703 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:09:12,703 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:09:12,703 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:09:12,704 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:12,704 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:09:12,708 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 53 nodes and edges [2021-12-17 15:09:12,709 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:09:12,709 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:09:12,709 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:09:12,710 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:09:12,710 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:12,710 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:12,725 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,725 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || !(2 <= \old(waterLevel))) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && pumpRunning == 0)) && ((((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(2 <= \old(waterLevel)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || (((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (((1 <= tmp && waterLevel == systemActive) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1))) && (((!(2 <= \old(waterLevel)) || ((((((((1 <= tmp && 1 <= tmp___0) && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && 1 <= \result) && pumpRunning == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) && \result == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) && ((((((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) && \result == 0) || (\result == 1 && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,726 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && tmp == 0) && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,727 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((((\result == 1 && \result == 0) && tmp == 1) && tmp___0 == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:09:12,727 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:12,727 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && pumpRunning == 0)) [2021-12-17 15:09:12,727 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) [2021-12-17 15:09:12,740 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:09:12,740 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:09:12,740 INFO L158 Benchmark]: Toolchain (without parser) took 7025.77ms. Allocated memory was 142.6MB in the beginning and 245.4MB in the end (delta: 102.8MB). Free memory was 110.8MB in the beginning and 104.1MB in the end (delta: 6.8MB). Peak memory consumption was 109.5MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,741 INFO L158 Benchmark]: CDTParser took 0.17ms. Allocated memory is still 83.9MB. Free memory was 43.5MB in the beginning and 43.5MB in the end (delta: 40.5kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:09:12,741 INFO L158 Benchmark]: CACSL2BoogieTranslator took 513.06ms. Allocated memory is still 142.6MB. Free memory was 110.5MB in the beginning and 107.4MB in the end (delta: 3.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,741 INFO L158 Benchmark]: Boogie Procedure Inliner took 53.16ms. Allocated memory is still 142.6MB. Free memory was 107.4MB in the beginning and 104.9MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,741 INFO L158 Benchmark]: Boogie Preprocessor took 43.14ms. Allocated memory is still 142.6MB. Free memory was 104.9MB in the beginning and 103.2MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,742 INFO L158 Benchmark]: RCFGBuilder took 418.64ms. Allocated memory is still 142.6MB. Free memory was 103.2MB in the beginning and 87.2MB in the end (delta: 16.0MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,742 INFO L158 Benchmark]: TraceAbstraction took 5948.56ms. Allocated memory was 142.6MB in the beginning and 245.4MB in the end (delta: 102.8MB). Free memory was 86.8MB in the beginning and 111.4MB in the end (delta: -24.6MB). Peak memory consumption was 89.5MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,742 INFO L158 Benchmark]: Witness Printer took 43.58ms. Allocated memory is still 245.4MB. Free memory was 110.4MB in the beginning and 104.1MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-17 15:09:12,743 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.17ms. Allocated memory is still 83.9MB. Free memory was 43.5MB in the beginning and 43.5MB in the end (delta: 40.5kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 513.06ms. Allocated memory is still 142.6MB. Free memory was 110.5MB in the beginning and 107.4MB in the end (delta: 3.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 53.16ms. Allocated memory is still 142.6MB. Free memory was 107.4MB in the beginning and 104.9MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 43.14ms. Allocated memory is still 142.6MB. Free memory was 104.9MB in the beginning and 103.2MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 418.64ms. Allocated memory is still 142.6MB. Free memory was 103.2MB in the beginning and 87.2MB in the end (delta: 16.0MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. * TraceAbstraction took 5948.56ms. Allocated memory was 142.6MB in the beginning and 245.4MB in the end (delta: 102.8MB). Free memory was 86.8MB in the beginning and 111.4MB in the end (delta: -24.6MB). Peak memory consumption was 89.5MB. Max. memory is 16.1GB. * Witness Printer took 43.58ms. Allocated memory is still 245.4MB. Free memory was 110.4MB in the beginning and 104.1MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 553]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 83 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 5.9s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 1.9s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.6s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1575 SdHoareTripleChecker+Valid, 1.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1554 mSDsluCounter, 3853 SdHoareTripleChecker+Invalid, 0.8s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2718 mSDsCounter, 336 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1526 IncrementalHoareTripleChecker+Invalid, 1862 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 336 mSolverCounterUnsat, 1135 mSDtfsCounter, 1526 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 474 GetRequests, 349 SyntacticMatches, 7 SemanticMatches, 118 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 363 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=565occurred in iteration=11, InterpolantAutomatonStates: 116, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 233 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 39 LocationsWithAnnotation, 962 PreInvPairs, 1045 NumberOfFragments, 956 HoareAnnotationTreeSize, 962 FomulaSimplifications, 1987 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 39 FomulaSimplificationsInter, 5251 FormulaSimplificationTreeSizeReductionInter, 1.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.1s InterpolantComputationTime, 797 NumberOfCodeBlocks, 797 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 860 ConstructedInterpolants, 0 QuantifiedInterpolants, 1683 SizeOfPredicates, 8 NumberOfNonLiveVariables, 951 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 15 InterpolantComputations, 11 PerfectInterpolantSequences, 264/294 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 576]: Loop Invariant Derived loop invariant: (waterLevel == systemActive && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 677]: Loop Invariant Derived loop invariant: (((((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) && \result == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) && ((((((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) && \result == 0) || (\result == 1 && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: ((((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (((1 <= tmp && waterLevel == systemActive) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1))) && (((!(2 <= \old(waterLevel)) || ((((((((1 <= tmp && 1 <= tmp___0) && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && 1 <= \result) && pumpRunning == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) - InvariantResult [Line: 569]: Loop Invariant Derived loop invariant: (waterLevel == systemActive && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 900]: Loop Invariant Derived loop invariant: ((splverifierCounter == 0 && 2 <= waterLevel) && systemActive == 1) || (((splverifierCounter == 0 && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 457]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 817]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 909]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 798]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && pumpRunning == 0)) - InvariantResult [Line: 583]: Loop Invariant Derived loop invariant: (waterLevel == systemActive && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 668]: Loop Invariant Derived loop invariant: (((!(2 <= \old(waterLevel)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || (((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 862]: Loop Invariant Derived loop invariant: (((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((((\result == 1 && \result == 0) && tmp == 1) && tmp___0 == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 525]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 600]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 881]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && tmp == 0) && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 919]: Loop Invariant Derived loop invariant: ((splverifierCounter == 0 && 2 <= waterLevel) && systemActive == 1) || (((splverifierCounter == 0 && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 691]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 447]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 765]: Loop Invariant Derived loop invariant: (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || !(2 <= \old(waterLevel))) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= tmp) && tmp == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && pumpRunning == 0)) && ((((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 504]: Loop Invariant Derived loop invariant: (waterLevel == systemActive && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 790]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) - InvariantResult [Line: 512]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:09:12,775 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE