./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 1741a5d4e19b6faba6ff51056891b76c8b4c0acd4f550f71706571820842dcfa --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:09:07,586 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:09:07,588 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:09:07,624 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:09:07,624 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:09:07,627 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:09:07,628 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:09:07,630 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:09:07,631 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:09:07,635 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:09:07,635 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:09:07,636 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:09:07,636 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:09:07,638 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:09:07,639 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:09:07,642 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:09:07,642 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:09:07,643 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:09:07,646 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:09:07,647 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:09:07,650 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:09:07,650 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:09:07,652 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:09:07,652 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:09:07,656 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:09:07,656 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:09:07,656 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:09:07,657 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:09:07,657 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:09:07,658 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:09:07,658 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:09:07,658 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:09:07,659 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:09:07,659 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:09:07,660 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:09:07,660 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:09:07,661 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:09:07,661 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:09:07,661 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:09:07,662 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:09:07,662 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:09:07,663 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:09:07,677 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:09:07,677 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:09:07,677 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:09:07,678 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:09:07,678 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:09:07,678 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:09:07,679 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:09:07,679 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:09:07,679 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:09:07,679 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:09:07,680 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:09:07,681 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:09:07,681 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:09:07,681 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:09:07,681 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:09:07,681 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:09:07,681 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:09:07,682 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:09:07,682 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:09:07,682 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:07,682 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:09:07,682 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:09:07,683 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:09:07,684 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:09:07,684 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 1741a5d4e19b6faba6ff51056891b76c8b4c0acd4f550f71706571820842dcfa [2021-12-17 15:09:07,837 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:09:07,865 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:09:07,867 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:09:07,868 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:09:07,868 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:09:07,869 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c [2021-12-17 15:09:07,929 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1b93ce106/d1da81a0d1b546d88717d0c6bfbfa3f9/FLAG9603fa8f8 [2021-12-17 15:09:08,284 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:09:08,284 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c [2021-12-17 15:09:08,292 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1b93ce106/d1da81a0d1b546d88717d0c6bfbfa3f9/FLAG9603fa8f8 [2021-12-17 15:09:08,697 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1b93ce106/d1da81a0d1b546d88717d0c6bfbfa3f9 [2021-12-17 15:09:08,699 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:09:08,700 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:09:08,701 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:08,701 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:09:08,705 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:09:08,705 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:08" (1/1) ... [2021-12-17 15:09:08,706 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@2dff861c and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:08, skipping insertion in model container [2021-12-17 15:09:08,706 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:08" (1/1) ... [2021-12-17 15:09:08,710 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:09:08,744 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:09:08,890 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c[6887,6900] [2021-12-17 15:09:08,950 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:08,956 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:09:08,980 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c[6887,6900] [2021-12-17 15:09:09,022 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:09,039 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:09:09,044 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09 WrapperNode [2021-12-17 15:09:09,044 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:09,045 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:09,045 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:09:09,045 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:09:09,051 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,067 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,090 INFO L137 Inliner]: procedures = 57, calls = 160, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 286 [2021-12-17 15:09:09,090 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:09,091 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:09:09,091 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:09:09,091 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:09:09,098 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,099 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,101 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,101 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,106 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,111 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,112 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,115 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:09:09,116 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:09:09,116 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:09:09,116 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:09:09,117 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (1/1) ... [2021-12-17 15:09:09,141 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:09,153 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:09,169 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:09:09,173 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:09:09,196 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:09:09,196 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:09:09,196 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:09:09,197 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:09:09,197 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:09:09,197 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:09:09,197 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:09:09,197 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:09,197 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:09,197 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:09:09,198 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:09:09,198 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:09:09,198 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:09:09,198 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-17 15:09:09,198 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-17 15:09:09,198 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:09:09,198 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:09:09,198 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:09:09,199 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:09:09,199 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:09:09,256 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:09:09,257 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:09:09,521 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:09:09,526 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:09:09,526 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:09:09,528 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:09 BoogieIcfgContainer [2021-12-17 15:09:09,529 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:09:09,530 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:09:09,530 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:09:09,534 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:09:09,534 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:09:08" (1/3) ... [2021-12-17 15:09:09,534 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@23286cac and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:09, skipping insertion in model container [2021-12-17 15:09:09,536 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:09" (2/3) ... [2021-12-17 15:09:09,536 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@23286cac and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:09, skipping insertion in model container [2021-12-17 15:09:09,536 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:09" (3/3) ... [2021-12-17 15:09:09,537 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product55.cil.c [2021-12-17 15:09:09,540 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:09:09,541 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:09:09,569 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:09:09,574 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:09:09,574 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:09:09,598 INFO L276 IsEmpty]: Start isEmpty. Operand has 99 states, 74 states have (on average 1.3918918918918919) internal successors, (103), 85 states have internal predecessors, (103), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-17 15:09:09,602 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2021-12-17 15:09:09,606 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:09,606 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:09,606 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:09,610 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:09,610 INFO L85 PathProgramCache]: Analyzing trace with hash -405346600, now seen corresponding path program 1 times [2021-12-17 15:09:09,616 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:09,616 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [912629337] [2021-12-17 15:09:09,616 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:09,617 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:09,720 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,776 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:09,777 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:09,777 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [912629337] [2021-12-17 15:09:09,778 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [912629337] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:09,779 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:09,779 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:09,780 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [374672686] [2021-12-17 15:09:09,781 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:09,783 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:09:09,784 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:09,805 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:09:09,806 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:09,808 INFO L87 Difference]: Start difference. First operand has 99 states, 74 states have (on average 1.3918918918918919) internal successors, (103), 85 states have internal predecessors, (103), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:09,853 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:09,853 INFO L93 Difference]: Finished difference Result 190 states and 261 transitions. [2021-12-17 15:09:09,854 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:09:09,855 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2021-12-17 15:09:09,856 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:09,864 INFO L225 Difference]: With dead ends: 190 [2021-12-17 15:09:09,864 INFO L226 Difference]: Without dead ends: 90 [2021-12-17 15:09:09,868 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:09,871 INFO L933 BasicCegarLoop]: 127 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 127 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:09,872 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 127 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:09,883 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 90 states. [2021-12-17 15:09:09,906 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 90 to 90. [2021-12-17 15:09:09,907 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 90 states, 67 states have (on average 1.328358208955224) internal successors, (89), 77 states have internal predecessors, (89), 15 states have call successors, (15), 8 states have call predecessors, (15), 7 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2021-12-17 15:09:09,912 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 90 states to 90 states and 118 transitions. [2021-12-17 15:09:09,914 INFO L78 Accepts]: Start accepts. Automaton has 90 states and 118 transitions. Word has length 19 [2021-12-17 15:09:09,914 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:09,914 INFO L470 AbstractCegarLoop]: Abstraction has 90 states and 118 transitions. [2021-12-17 15:09:09,914 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:09,915 INFO L276 IsEmpty]: Start isEmpty. Operand 90 states and 118 transitions. [2021-12-17 15:09:09,918 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2021-12-17 15:09:09,918 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:09,918 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:09,918 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:09:09,919 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:09,922 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:09,922 INFO L85 PathProgramCache]: Analyzing trace with hash 1370466006, now seen corresponding path program 1 times [2021-12-17 15:09:09,923 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:09,923 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1691780] [2021-12-17 15:09:09,923 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:09,923 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:09,956 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:09,997 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:09,997 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:09,998 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1691780] [2021-12-17 15:09:09,998 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1691780] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:09,998 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:09,998 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:09:09,998 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1607698220] [2021-12-17 15:09:09,998 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:09,999 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:10,000 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,000 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:10,000 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,001 INFO L87 Difference]: Start difference. First operand 90 states and 118 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,014 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,015 INFO L93 Difference]: Finished difference Result 142 states and 186 transitions. [2021-12-17 15:09:10,015 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:10,015 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2021-12-17 15:09:10,015 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,016 INFO L225 Difference]: With dead ends: 142 [2021-12-17 15:09:10,016 INFO L226 Difference]: Without dead ends: 81 [2021-12-17 15:09:10,017 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,018 INFO L933 BasicCegarLoop]: 105 mSDtfsCounter, 16 mSDsluCounter, 84 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 189 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,019 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 189 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:10,019 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 81 states. [2021-12-17 15:09:10,025 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 81 to 81. [2021-12-17 15:09:10,025 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 81 states, 61 states have (on average 1.3442622950819672) internal successors, (82), 71 states have internal predecessors, (82), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 7 states have call predecessors, (12), 12 states have call successors, (12) [2021-12-17 15:09:10,026 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 81 states to 81 states and 106 transitions. [2021-12-17 15:09:10,026 INFO L78 Accepts]: Start accepts. Automaton has 81 states and 106 transitions. Word has length 20 [2021-12-17 15:09:10,026 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,026 INFO L470 AbstractCegarLoop]: Abstraction has 81 states and 106 transitions. [2021-12-17 15:09:10,027 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,027 INFO L276 IsEmpty]: Start isEmpty. Operand 81 states and 106 transitions. [2021-12-17 15:09:10,027 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-17 15:09:10,027 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,028 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,028 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:09:10,028 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,028 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,029 INFO L85 PathProgramCache]: Analyzing trace with hash 412043634, now seen corresponding path program 1 times [2021-12-17 15:09:10,029 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,029 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [597303907] [2021-12-17 15:09:10,029 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,029 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,042 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,081 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:10,082 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,083 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [597303907] [2021-12-17 15:09:10,083 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [597303907] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,083 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,084 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:10,084 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [32492005] [2021-12-17 15:09:10,084 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,085 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:10,085 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,086 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:10,086 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,086 INFO L87 Difference]: Start difference. First operand 81 states and 106 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,109 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,110 INFO L93 Difference]: Finished difference Result 228 states and 304 transitions. [2021-12-17 15:09:10,110 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:10,110 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2021-12-17 15:09:10,110 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,112 INFO L225 Difference]: With dead ends: 228 [2021-12-17 15:09:10,112 INFO L226 Difference]: Without dead ends: 154 [2021-12-17 15:09:10,113 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,114 INFO L933 BasicCegarLoop]: 128 mSDtfsCounter, 86 mSDsluCounter, 96 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 86 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,114 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [86 Valid, 224 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:10,115 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 154 states. [2021-12-17 15:09:10,129 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 154 to 151. [2021-12-17 15:09:10,129 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 151 states, 112 states have (on average 1.3660714285714286) internal successors, (153), 131 states have internal predecessors, (153), 24 states have call successors, (24), 14 states have call predecessors, (24), 14 states have return successors, (24), 13 states have call predecessors, (24), 24 states have call successors, (24) [2021-12-17 15:09:10,130 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 151 states to 151 states and 201 transitions. [2021-12-17 15:09:10,130 INFO L78 Accepts]: Start accepts. Automaton has 151 states and 201 transitions. Word has length 24 [2021-12-17 15:09:10,130 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,131 INFO L470 AbstractCegarLoop]: Abstraction has 151 states and 201 transitions. [2021-12-17 15:09:10,131 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,131 INFO L276 IsEmpty]: Start isEmpty. Operand 151 states and 201 transitions. [2021-12-17 15:09:10,132 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2021-12-17 15:09:10,134 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,134 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,134 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:09:10,134 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,135 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,135 INFO L85 PathProgramCache]: Analyzing trace with hash 2062247464, now seen corresponding path program 1 times [2021-12-17 15:09:10,135 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,135 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1136615490] [2021-12-17 15:09:10,135 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,143 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,170 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,206 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:10,207 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,207 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1136615490] [2021-12-17 15:09:10,207 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1136615490] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,207 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,207 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-12-17 15:09:10,207 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [445922845] [2021-12-17 15:09:10,208 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,208 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:10,208 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,208 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:10,209 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:10,209 INFO L87 Difference]: Start difference. First operand 151 states and 201 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,276 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,276 INFO L93 Difference]: Finished difference Result 427 states and 592 transitions. [2021-12-17 15:09:10,279 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:09:10,280 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2021-12-17 15:09:10,280 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,282 INFO L225 Difference]: With dead ends: 427 [2021-12-17 15:09:10,285 INFO L226 Difference]: Without dead ends: 283 [2021-12-17 15:09:10,286 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:10,287 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 77 mSDsluCounter, 315 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 77 SdHoareTripleChecker+Valid, 426 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,290 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [77 Valid, 426 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:10,291 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 283 states. [2021-12-17 15:09:10,308 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 283 to 283. [2021-12-17 15:09:10,309 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 283 states, 208 states have (on average 1.3461538461538463) internal successors, (280), 243 states have internal predecessors, (280), 48 states have call successors, (48), 28 states have call predecessors, (48), 26 states have return successors, (50), 24 states have call predecessors, (50), 48 states have call successors, (50) [2021-12-17 15:09:10,310 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 283 states to 283 states and 378 transitions. [2021-12-17 15:09:10,311 INFO L78 Accepts]: Start accepts. Automaton has 283 states and 378 transitions. Word has length 28 [2021-12-17 15:09:10,311 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,311 INFO L470 AbstractCegarLoop]: Abstraction has 283 states and 378 transitions. [2021-12-17 15:09:10,311 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,311 INFO L276 IsEmpty]: Start isEmpty. Operand 283 states and 378 transitions. [2021-12-17 15:09:10,313 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2021-12-17 15:09:10,313 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,313 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,314 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:09:10,314 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,314 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,314 INFO L85 PathProgramCache]: Analyzing trace with hash -1056507795, now seen corresponding path program 1 times [2021-12-17 15:09:10,314 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,315 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [851890866] [2021-12-17 15:09:10,315 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,315 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,337 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,372 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:10,373 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,373 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [851890866] [2021-12-17 15:09:10,373 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [851890866] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,374 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,374 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:10,374 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1224395873] [2021-12-17 15:09:10,374 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,375 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:10,376 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,376 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:10,376 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,377 INFO L87 Difference]: Start difference. First operand 283 states and 378 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,419 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,419 INFO L93 Difference]: Finished difference Result 675 states and 925 transitions. [2021-12-17 15:09:10,420 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:10,420 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2021-12-17 15:09:10,420 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,422 INFO L225 Difference]: With dead ends: 675 [2021-12-17 15:09:10,423 INFO L226 Difference]: Without dead ends: 399 [2021-12-17 15:09:10,424 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:10,425 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 58 mSDsluCounter, 69 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 58 SdHoareTripleChecker+Valid, 180 SdHoareTripleChecker+Invalid, 23 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,425 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [58 Valid, 180 Invalid, 23 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:10,426 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 399 states. [2021-12-17 15:09:10,447 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 399 to 390. [2021-12-17 15:09:10,447 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 390 states, 295 states have (on average 1.2915254237288136) internal successors, (381), 317 states have internal predecessors, (381), 49 states have call successors, (49), 45 states have call predecessors, (49), 45 states have return successors, (73), 44 states have call predecessors, (73), 49 states have call successors, (73) [2021-12-17 15:09:10,449 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 390 states to 390 states and 503 transitions. [2021-12-17 15:09:10,449 INFO L78 Accepts]: Start accepts. Automaton has 390 states and 503 transitions. Word has length 30 [2021-12-17 15:09:10,450 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,450 INFO L470 AbstractCegarLoop]: Abstraction has 390 states and 503 transitions. [2021-12-17 15:09:10,450 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:10,450 INFO L276 IsEmpty]: Start isEmpty. Operand 390 states and 503 transitions. [2021-12-17 15:09:10,451 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-17 15:09:10,451 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,451 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,451 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:09:10,452 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,452 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,452 INFO L85 PathProgramCache]: Analyzing trace with hash -1410993586, now seen corresponding path program 1 times [2021-12-17 15:09:10,452 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,452 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1391937966] [2021-12-17 15:09:10,452 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,453 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,461 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,493 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:10,495 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,497 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:10,498 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,498 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1391937966] [2021-12-17 15:09:10,498 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1391937966] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,498 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,498 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:10,499 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1968025804] [2021-12-17 15:09:10,499 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,499 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:10,499 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,500 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:10,500 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:10,500 INFO L87 Difference]: Start difference. First operand 390 states and 503 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:10,727 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:10,727 INFO L93 Difference]: Finished difference Result 480 states and 622 transitions. [2021-12-17 15:09:10,728 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2021-12-17 15:09:10,728 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2021-12-17 15:09:10,728 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:10,733 INFO L225 Difference]: With dead ends: 480 [2021-12-17 15:09:10,733 INFO L226 Difference]: Without dead ends: 478 [2021-12-17 15:09:10,734 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:10,739 INFO L933 BasicCegarLoop]: 113 mSDtfsCounter, 138 mSDsluCounter, 286 mSDsCounter, 0 mSdLazyCounter, 197 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 144 SdHoareTripleChecker+Valid, 399 SdHoareTripleChecker+Invalid, 239 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 197 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:10,740 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [144 Valid, 399 Invalid, 239 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 197 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:10,741 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 478 states. [2021-12-17 15:09:10,760 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 478 to 452. [2021-12-17 15:09:10,761 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 452 states, 343 states have (on average 1.2769679300291545) internal successors, (438), 375 states have internal predecessors, (438), 55 states have call successors, (55), 45 states have call predecessors, (55), 53 states have return successors, (91), 48 states have call predecessors, (91), 55 states have call successors, (91) [2021-12-17 15:09:10,763 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 452 states to 452 states and 584 transitions. [2021-12-17 15:09:10,765 INFO L78 Accepts]: Start accepts. Automaton has 452 states and 584 transitions. Word has length 32 [2021-12-17 15:09:10,765 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:10,765 INFO L470 AbstractCegarLoop]: Abstraction has 452 states and 584 transitions. [2021-12-17 15:09:10,766 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:09:10,766 INFO L276 IsEmpty]: Start isEmpty. Operand 452 states and 584 transitions. [2021-12-17 15:09:10,767 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:09:10,769 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:10,769 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:10,769 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:09:10,769 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:10,769 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:10,770 INFO L85 PathProgramCache]: Analyzing trace with hash -1995340570, now seen corresponding path program 1 times [2021-12-17 15:09:10,770 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:10,770 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [258532277] [2021-12-17 15:09:10,770 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:10,771 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:10,779 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:10,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,804 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-17 15:09:10,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,811 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:10,813 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:10,833 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:10,833 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:10,833 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [258532277] [2021-12-17 15:09:10,833 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [258532277] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:10,833 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:10,833 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:10,833 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [825511534] [2021-12-17 15:09:10,833 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:10,834 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:10,834 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:10,834 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:10,834 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:10,834 INFO L87 Difference]: Start difference. First operand 452 states and 584 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:11,069 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,069 INFO L93 Difference]: Finished difference Result 1011 states and 1330 transitions. [2021-12-17 15:09:11,070 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:09:11,070 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2021-12-17 15:09:11,070 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,072 INFO L225 Difference]: With dead ends: 1011 [2021-12-17 15:09:11,073 INFO L226 Difference]: Without dead ends: 566 [2021-12-17 15:09:11,074 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:11,074 INFO L933 BasicCegarLoop]: 98 mSDtfsCounter, 144 mSDsluCounter, 284 mSDsCounter, 0 mSdLazyCounter, 256 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 144 SdHoareTripleChecker+Valid, 382 SdHoareTripleChecker+Invalid, 306 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 256 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,075 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [144 Valid, 382 Invalid, 306 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 256 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:09:11,075 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 566 states. [2021-12-17 15:09:11,099 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 566 to 512. [2021-12-17 15:09:11,100 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 512 states, 393 states have (on average 1.256997455470738) internal successors, (494), 425 states have internal predecessors, (494), 55 states have call successors, (55), 45 states have call predecessors, (55), 63 states have return successors, (105), 56 states have call predecessors, (105), 55 states have call successors, (105) [2021-12-17 15:09:11,103 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 512 states to 512 states and 654 transitions. [2021-12-17 15:09:11,103 INFO L78 Accepts]: Start accepts. Automaton has 512 states and 654 transitions. Word has length 47 [2021-12-17 15:09:11,105 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,105 INFO L470 AbstractCegarLoop]: Abstraction has 512 states and 654 transitions. [2021-12-17 15:09:11,105 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:11,105 INFO L276 IsEmpty]: Start isEmpty. Operand 512 states and 654 transitions. [2021-12-17 15:09:11,107 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:09:11,107 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:11,108 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:11,108 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:09:11,108 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:11,108 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:11,108 INFO L85 PathProgramCache]: Analyzing trace with hash 1278558372, now seen corresponding path program 1 times [2021-12-17 15:09:11,109 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:11,109 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [853839666] [2021-12-17 15:09:11,109 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:11,109 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:11,127 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,162 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:11,164 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,171 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-17 15:09:11,181 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,187 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:11,190 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,214 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:11,214 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:11,215 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [853839666] [2021-12-17 15:09:11,215 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [853839666] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:11,215 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:11,215 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:11,215 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [656428247] [2021-12-17 15:09:11,215 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:11,216 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:11,216 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:11,216 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:11,216 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:11,216 INFO L87 Difference]: Start difference. First operand 512 states and 654 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:09:11,535 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,536 INFO L93 Difference]: Finished difference Result 1022 states and 1338 transitions. [2021-12-17 15:09:11,536 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-17 15:09:11,536 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 47 [2021-12-17 15:09:11,537 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,539 INFO L225 Difference]: With dead ends: 1022 [2021-12-17 15:09:11,539 INFO L226 Difference]: Without dead ends: 517 [2021-12-17 15:09:11,541 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 26 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 41 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=90, Invalid=182, Unknown=0, NotChecked=0, Total=272 [2021-12-17 15:09:11,541 INFO L933 BasicCegarLoop]: 110 mSDtfsCounter, 401 mSDsluCounter, 307 mSDsCounter, 0 mSdLazyCounter, 318 mSolverCounterSat, 149 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 406 SdHoareTripleChecker+Valid, 417 SdHoareTripleChecker+Invalid, 467 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 149 IncrementalHoareTripleChecker+Valid, 318 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,541 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [406 Valid, 417 Invalid, 467 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [149 Valid, 318 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:09:11,542 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 517 states. [2021-12-17 15:09:11,554 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 517 to 403. [2021-12-17 15:09:11,555 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 403 states, 308 states have (on average 1.2532467532467533) internal successors, (386), 333 states have internal predecessors, (386), 46 states have call successors, (46), 38 states have call predecessors, (46), 48 states have return successors, (78), 43 states have call predecessors, (78), 46 states have call successors, (78) [2021-12-17 15:09:11,556 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 403 states to 403 states and 510 transitions. [2021-12-17 15:09:11,557 INFO L78 Accepts]: Start accepts. Automaton has 403 states and 510 transitions. Word has length 47 [2021-12-17 15:09:11,557 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,557 INFO L470 AbstractCegarLoop]: Abstraction has 403 states and 510 transitions. [2021-12-17 15:09:11,557 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:09:11,557 INFO L276 IsEmpty]: Start isEmpty. Operand 403 states and 510 transitions. [2021-12-17 15:09:11,558 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:09:11,558 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:11,558 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:11,558 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:09:11,559 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:11,559 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:11,559 INFO L85 PathProgramCache]: Analyzing trace with hash -715586334, now seen corresponding path program 1 times [2021-12-17 15:09:11,559 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:11,559 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [869259626] [2021-12-17 15:09:11,559 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:11,560 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:11,566 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,600 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:11,601 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,606 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-17 15:09:11,609 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,615 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:11,619 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,626 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:11,626 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:11,626 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [869259626] [2021-12-17 15:09:11,626 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [869259626] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:11,626 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:11,626 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:11,627 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1701153172] [2021-12-17 15:09:11,627 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:11,628 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:11,628 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:11,628 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:11,629 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:11,629 INFO L87 Difference]: Start difference. First operand 403 states and 510 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:11,909 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:11,910 INFO L93 Difference]: Finished difference Result 927 states and 1246 transitions. [2021-12-17 15:09:11,910 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2021-12-17 15:09:11,910 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2021-12-17 15:09:11,910 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:11,913 INFO L225 Difference]: With dead ends: 927 [2021-12-17 15:09:11,913 INFO L226 Difference]: Without dead ends: 624 [2021-12-17 15:09:11,914 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 54 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2021-12-17 15:09:11,914 INFO L933 BasicCegarLoop]: 142 mSDtfsCounter, 205 mSDsluCounter, 351 mSDsCounter, 0 mSdLazyCounter, 358 mSolverCounterSat, 79 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 207 SdHoareTripleChecker+Valid, 493 SdHoareTripleChecker+Invalid, 437 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 79 IncrementalHoareTripleChecker+Valid, 358 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:11,914 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [207 Valid, 493 Invalid, 437 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [79 Valid, 358 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:09:11,915 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 624 states. [2021-12-17 15:09:11,930 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 624 to 599. [2021-12-17 15:09:11,931 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 599 states, 460 states have (on average 1.2260869565217392) internal successors, (564), 492 states have internal predecessors, (564), 67 states have call successors, (67), 57 states have call predecessors, (67), 71 states have return successors, (141), 70 states have call predecessors, (141), 67 states have call successors, (141) [2021-12-17 15:09:11,933 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 599 states to 599 states and 772 transitions. [2021-12-17 15:09:11,933 INFO L78 Accepts]: Start accepts. Automaton has 599 states and 772 transitions. Word has length 47 [2021-12-17 15:09:11,933 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:11,933 INFO L470 AbstractCegarLoop]: Abstraction has 599 states and 772 transitions. [2021-12-17 15:09:11,933 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:09:11,933 INFO L276 IsEmpty]: Start isEmpty. Operand 599 states and 772 transitions. [2021-12-17 15:09:11,934 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2021-12-17 15:09:11,934 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:11,935 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:11,935 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:09:11,935 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:11,935 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:11,935 INFO L85 PathProgramCache]: Analyzing trace with hash -361612340, now seen corresponding path program 1 times [2021-12-17 15:09:11,935 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:11,935 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [320396077] [2021-12-17 15:09:11,935 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:11,935 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:11,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,955 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:11,955 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,960 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-17 15:09:11,962 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,972 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:11,974 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,976 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:11,977 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:11,985 INFO L134 CoverageAnalysis]: Checked inductivity of 14 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:11,986 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:11,986 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [320396077] [2021-12-17 15:09:11,986 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [320396077] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:11,986 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:11,986 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:11,986 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1763266071] [2021-12-17 15:09:11,986 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:11,986 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:11,986 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:11,987 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:11,987 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=29, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:11,987 INFO L87 Difference]: Start difference. First operand 599 states and 772 transitions. Second operand has 7 states, 7 states have (on average 8.714285714285714) internal successors, (61), 4 states have internal predecessors, (61), 4 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:12,158 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:12,158 INFO L93 Difference]: Finished difference Result 710 states and 912 transitions. [2021-12-17 15:09:12,159 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:09:12,159 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 8.714285714285714) internal successors, (61), 4 states have internal predecessors, (61), 4 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 70 [2021-12-17 15:09:12,160 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:12,161 INFO L225 Difference]: With dead ends: 710 [2021-12-17 15:09:12,161 INFO L226 Difference]: Without dead ends: 306 [2021-12-17 15:09:12,162 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:09:12,163 INFO L933 BasicCegarLoop]: 124 mSDtfsCounter, 278 mSDsluCounter, 177 mSDsCounter, 0 mSdLazyCounter, 202 mSolverCounterSat, 78 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 286 SdHoareTripleChecker+Valid, 301 SdHoareTripleChecker+Invalid, 280 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 78 IncrementalHoareTripleChecker+Valid, 202 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:12,165 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [286 Valid, 301 Invalid, 280 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [78 Valid, 202 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:12,166 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2021-12-17 15:09:12,185 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 295. [2021-12-17 15:09:12,186 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 295 states, 227 states have (on average 1.1894273127753303) internal successors, (270), 242 states have internal predecessors, (270), 32 states have call successors, (32), 28 states have call predecessors, (32), 35 states have return successors, (69), 34 states have call predecessors, (69), 32 states have call successors, (69) [2021-12-17 15:09:12,187 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 295 states to 295 states and 371 transitions. [2021-12-17 15:09:12,187 INFO L78 Accepts]: Start accepts. Automaton has 295 states and 371 transitions. Word has length 70 [2021-12-17 15:09:12,187 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:12,187 INFO L470 AbstractCegarLoop]: Abstraction has 295 states and 371 transitions. [2021-12-17 15:09:12,188 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 8.714285714285714) internal successors, (61), 4 states have internal predecessors, (61), 4 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:12,188 INFO L276 IsEmpty]: Start isEmpty. Operand 295 states and 371 transitions. [2021-12-17 15:09:12,191 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2021-12-17 15:09:12,191 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:12,192 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:12,192 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-17 15:09:12,192 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:12,192 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:12,193 INFO L85 PathProgramCache]: Analyzing trace with hash -1870420981, now seen corresponding path program 1 times [2021-12-17 15:09:12,193 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:12,193 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1444683444] [2021-12-17 15:09:12,193 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:12,193 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:12,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,257 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:12,258 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,266 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:12,268 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,286 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:12,288 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,295 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:12,296 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,303 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2021-12-17 15:09:12,305 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,307 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-17 15:09:12,308 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,313 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:12,313 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,315 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 11 proven. 9 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2021-12-17 15:09:12,315 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:12,315 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1444683444] [2021-12-17 15:09:12,315 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1444683444] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:12,315 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1741855592] [2021-12-17 15:09:12,316 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:12,316 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:12,316 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:12,317 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:12,342 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:09:12,398 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:12,401 INFO L263 TraceCheckSpWp]: Trace formula consists of 454 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-17 15:09:12,406 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:12,658 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 16 proven. 8 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:12,658 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:09:12,814 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 12 proven. 8 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2021-12-17 15:09:12,814 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1741855592] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:09:12,816 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:09:12,816 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2021-12-17 15:09:12,816 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [621524445] [2021-12-17 15:09:12,817 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:09:12,817 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2021-12-17 15:09:12,817 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:12,817 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2021-12-17 15:09:12,818 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:09:12,818 INFO L87 Difference]: Start difference. First operand 295 states and 371 transitions. Second operand has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2021-12-17 15:09:13,365 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:13,365 INFO L93 Difference]: Finished difference Result 701 states and 935 transitions. [2021-12-17 15:09:13,365 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2021-12-17 15:09:13,366 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) Word has length 89 [2021-12-17 15:09:13,366 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:13,369 INFO L225 Difference]: With dead ends: 701 [2021-12-17 15:09:13,370 INFO L226 Difference]: Without dead ends: 458 [2021-12-17 15:09:13,371 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 226 GetRequests, 195 SyntacticMatches, 4 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 196 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2021-12-17 15:09:13,372 INFO L933 BasicCegarLoop]: 137 mSDtfsCounter, 340 mSDsluCounter, 386 mSDsCounter, 0 mSdLazyCounter, 543 mSolverCounterSat, 157 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 344 SdHoareTripleChecker+Valid, 523 SdHoareTripleChecker+Invalid, 700 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 157 IncrementalHoareTripleChecker+Valid, 543 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:13,372 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [344 Valid, 523 Invalid, 700 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [157 Valid, 543 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:09:13,373 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 458 states. [2021-12-17 15:09:13,388 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 458 to 408. [2021-12-17 15:09:13,389 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 408 states, 310 states have (on average 1.196774193548387) internal successors, (371), 332 states have internal predecessors, (371), 47 states have call successors, (47), 41 states have call predecessors, (47), 50 states have return successors, (107), 46 states have call predecessors, (107), 47 states have call successors, (107) [2021-12-17 15:09:13,391 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 408 states to 408 states and 525 transitions. [2021-12-17 15:09:13,391 INFO L78 Accepts]: Start accepts. Automaton has 408 states and 525 transitions. Word has length 89 [2021-12-17 15:09:13,392 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:13,392 INFO L470 AbstractCegarLoop]: Abstraction has 408 states and 525 transitions. [2021-12-17 15:09:13,393 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2021-12-17 15:09:13,393 INFO L276 IsEmpty]: Start isEmpty. Operand 408 states and 525 transitions. [2021-12-17 15:09:13,394 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2021-12-17 15:09:13,395 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:13,395 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:13,437 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:09:13,611 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:09:13,611 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:13,612 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:13,612 INFO L85 PathProgramCache]: Analyzing trace with hash 309477364, now seen corresponding path program 2 times [2021-12-17 15:09:13,612 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:13,612 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1424486410] [2021-12-17 15:09:13,612 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:13,612 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:13,652 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,688 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:13,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,696 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:13,699 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,717 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:13,719 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:13,725 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,730 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2021-12-17 15:09:13,734 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,765 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:13,769 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-17 15:09:13,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,803 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:13,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,805 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2021-12-17 15:09:13,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-17 15:09:13,809 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,811 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:13,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:13,813 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 49 proven. 23 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2021-12-17 15:09:13,813 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:13,813 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1424486410] [2021-12-17 15:09:13,813 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1424486410] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:13,813 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [328559845] [2021-12-17 15:09:13,813 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2021-12-17 15:09:13,814 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:13,814 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:13,815 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:13,867 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:09:13,964 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2021-12-17 15:09:13,964 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2021-12-17 15:09:13,966 INFO L263 TraceCheckSpWp]: Trace formula consists of 562 conjuncts, 10 conjunts are in the unsatisfiable core [2021-12-17 15:09:13,969 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:14,230 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 76 proven. 0 refuted. 0 times theorem prover too weak. 14 trivial. 0 not checked. [2021-12-17 15:09:14,231 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:09:14,231 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [328559845] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:14,231 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:09:14,231 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [12] total 15 [2021-12-17 15:09:14,231 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1128264750] [2021-12-17 15:09:14,231 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:14,232 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:14,232 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:14,232 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:14,232 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=44, Invalid=166, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:09:14,232 INFO L87 Difference]: Start difference. First operand 408 states and 525 transitions. Second operand has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2021-12-17 15:09:14,500 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:14,500 INFO L93 Difference]: Finished difference Result 1098 states and 1482 transitions. [2021-12-17 15:09:14,500 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2021-12-17 15:09:14,501 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) Word has length 131 [2021-12-17 15:09:14,501 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:14,504 INFO L225 Difference]: With dead ends: 1098 [2021-12-17 15:09:14,505 INFO L226 Difference]: Without dead ends: 741 [2021-12-17 15:09:14,507 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 172 GetRequests, 147 SyntacticMatches, 7 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 93 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=84, Invalid=296, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:09:14,507 INFO L933 BasicCegarLoop]: 171 mSDtfsCounter, 176 mSDsluCounter, 477 mSDsCounter, 0 mSdLazyCounter, 165 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 176 SdHoareTripleChecker+Valid, 648 SdHoareTripleChecker+Invalid, 196 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 165 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:14,508 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [176 Valid, 648 Invalid, 196 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 165 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:14,509 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 741 states. [2021-12-17 15:09:14,554 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 741 to 714. [2021-12-17 15:09:14,556 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 714 states, 541 states have (on average 1.1903881700554528) internal successors, (644), 571 states have internal predecessors, (644), 80 states have call successors, (80), 74 states have call predecessors, (80), 92 states have return successors, (174), 85 states have call predecessors, (174), 80 states have call successors, (174) [2021-12-17 15:09:14,559 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 714 states to 714 states and 898 transitions. [2021-12-17 15:09:14,559 INFO L78 Accepts]: Start accepts. Automaton has 714 states and 898 transitions. Word has length 131 [2021-12-17 15:09:14,560 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:14,560 INFO L470 AbstractCegarLoop]: Abstraction has 714 states and 898 transitions. [2021-12-17 15:09:14,560 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2021-12-17 15:09:14,561 INFO L276 IsEmpty]: Start isEmpty. Operand 714 states and 898 transitions. [2021-12-17 15:09:14,563 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2021-12-17 15:09:14,564 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:14,564 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:14,604 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2021-12-17 15:09:14,783 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-17 15:09:14,784 INFO L402 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:14,784 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:14,784 INFO L85 PathProgramCache]: Analyzing trace with hash -107919242, now seen corresponding path program 1 times [2021-12-17 15:09:14,784 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:14,784 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [785032962] [2021-12-17 15:09:14,784 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:14,785 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:14,798 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,817 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:09:14,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,824 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:09:14,826 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,832 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:09:14,833 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,836 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:14,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,842 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2021-12-17 15:09:14,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,850 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:14,853 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-17 15:09:14,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,874 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:14,874 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,876 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2021-12-17 15:09:14,878 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,880 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-17 15:09:14,881 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,883 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:14,884 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:14,885 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 43 proven. 15 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2021-12-17 15:09:14,885 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:14,885 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [785032962] [2021-12-17 15:09:14,886 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [785032962] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:14,886 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [863073558] [2021-12-17 15:09:14,886 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:14,886 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:14,886 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:14,900 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:14,967 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-12-17 15:09:15,038 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:15,041 INFO L263 TraceCheckSpWp]: Trace formula consists of 563 conjuncts, 5 conjunts are in the unsatisfiable core [2021-12-17 15:09:15,045 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:15,181 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 62 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2021-12-17 15:09:15,181 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:09:15,181 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [863073558] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:15,181 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:09:15,182 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 9 [2021-12-17 15:09:15,183 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1189872618] [2021-12-17 15:09:15,184 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:15,184 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:15,185 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:15,185 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:15,185 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=55, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:09:15,185 INFO L87 Difference]: Start difference. First operand 714 states and 898 transitions. Second operand has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2021-12-17 15:09:15,214 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:15,214 INFO L93 Difference]: Finished difference Result 972 states and 1211 transitions. [2021-12-17 15:09:15,214 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:09:15,215 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 131 [2021-12-17 15:09:15,215 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:15,215 INFO L225 Difference]: With dead ends: 972 [2021-12-17 15:09:15,215 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:09:15,217 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 163 GetRequests, 154 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=83, Unknown=0, NotChecked=0, Total=110 [2021-12-17 15:09:15,218 INFO L933 BasicCegarLoop]: 96 mSDtfsCounter, 9 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 367 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:15,218 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [9 Valid, 367 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:15,219 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:09:15,219 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:09:15,219 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:15,219 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:09:15,219 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 131 [2021-12-17 15:09:15,220 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:15,220 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:09:15,220 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2021-12-17 15:09:15,220 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:09:15,220 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:09:15,222 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:09:15,245 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-12-17 15:09:15,435 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:15,437 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:09:17,639 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 252 259) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or (not (= 1 ~systemActive~0)) .cse0) (or (= 0 ~systemActive~0) .cse0 (not (<= 2 ~waterLevel~0))))) [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 252 259) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 252 259) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 159 165) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 159 165) the Hoare annotation is: true [2021-12-17 15:09:17,639 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 933 944) the Hoare annotation is: true [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point L937-1(lines 933 944) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 933 944) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 446 475) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 446 475) the Hoare annotation is: true [2021-12-17 15:09:17,639 INFO L861 garLoopResultBuilder]: At program point L471(lines 446 475) the Hoare annotation is: true [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point L467(line 467) no Hoare annotation was computed. [2021-12-17 15:09:17,639 INFO L858 garLoopResultBuilder]: For program point L460(lines 460 464) no Hoare annotation was computed. [2021-12-17 15:09:17,640 INFO L861 garLoopResultBuilder]: At program point L460-1(lines 460 464) the Hoare annotation is: true [2021-12-17 15:09:17,640 INFO L858 garLoopResultBuilder]: For program point L457(line 457) no Hoare annotation was computed. [2021-12-17 15:09:17,640 INFO L861 garLoopResultBuilder]: At program point L456-2(lines 456 470) the Hoare annotation is: true [2021-12-17 15:09:17,640 INFO L861 garLoopResultBuilder]: At program point L452(line 452) the Hoare annotation is: true [2021-12-17 15:09:17,640 INFO L858 garLoopResultBuilder]: For program point L452-1(line 452) no Hoare annotation was computed. [2021-12-17 15:09:17,640 INFO L858 garLoopResultBuilder]: For program point L440(line 440) no Hoare annotation was computed. [2021-12-17 15:09:17,640 INFO L854 garLoopResultBuilder]: At program point L238(line 238) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 (not (= ~systemActive~0 0))) (or (not (= |old(~waterLevel~0)| 1)) (and .cse1 .cse2) .cse3 .cse0) (or (not (<= 2 |old(~waterLevel~0)|)) .cse3 (and .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2)))) [2021-12-17 15:09:17,640 INFO L854 garLoopResultBuilder]: At program point L238-1(lines 219 243) the Hoare annotation is: (let ((.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse3 (not (= ~systemActive~0 0))) (or (not (= |old(~waterLevel~0)| 1)) (and .cse2 .cse4) .cse1 .cse3) (or .cse0 (and (<= 1 ~waterLevel~0) .cse4) .cse1 (<= 2 ~waterLevel~0)))) [2021-12-17 15:09:17,640 INFO L854 garLoopResultBuilder]: At program point L267(lines 260 270) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))))) [2021-12-17 15:09:17,640 INFO L858 garLoopResultBuilder]: For program point L139-1(lines 138 157) no Hoare annotation was computed. [2021-12-17 15:09:17,641 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 135 158) no Hoare annotation was computed. [2021-12-17 15:09:17,641 INFO L854 garLoopResultBuilder]: At program point L441(lines 436 443) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1))) [2021-12-17 15:09:17,641 INFO L854 garLoopResultBuilder]: At program point L982(lines 977 985) the Hoare annotation is: (let ((.cse3 (not (= ~systemActive~0 0))) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse1 (= |timeShift_getWaterLevel_#res#1| 1)) (.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse8 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse5 (not (= 1 ~systemActive~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse2 (and .cse6 .cse7)) (or .cse4 .cse6 .cse2 .cse3) (or (and .cse7 .cse8) .cse2 .cse3) (or .cse4 (and (<= 1 ~waterLevel~0) (<= 1 |timeShift_getWaterLevel_#res#1|) .cse8) .cse5 (and .cse6 (<= 2 ~waterLevel~0))) (or (and .cse1 .cse7 .cse8) .cse0 .cse5 .cse2))) [2021-12-17 15:09:17,641 INFO L854 garLoopResultBuilder]: At program point L276(lines 271 279) the Hoare annotation is: (let ((.cse1 (not (= ~systemActive~0 0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 2 |old(~waterLevel~0)|))) (.cse3 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1) (or .cse2 .cse0 .cse1) (or (and (= |timeShift_isPumpRunning_#res#1| 0) (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) .cse0 .cse1) (or .cse3 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse2 .cse3))) [2021-12-17 15:09:17,641 INFO L858 garLoopResultBuilder]: For program point L227(lines 227 235) no Hoare annotation was computed. [2021-12-17 15:09:17,641 INFO L858 garLoopResultBuilder]: For program point L384(lines 384 390) no Hoare annotation was computed. [2021-12-17 15:09:17,641 INFO L858 garLoopResultBuilder]: For program point L223(lines 223 240) no Hoare annotation was computed. [2021-12-17 15:09:17,641 INFO L858 garLoopResultBuilder]: For program point L380(lines 380 393) no Hoare annotation was computed. [2021-12-17 15:09:17,642 INFO L854 garLoopResultBuilder]: At program point L380-1(lines 372 396) the Hoare annotation is: (let ((.cse4 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse5 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|)) (.cse11 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse10 (<= 2 ~waterLevel~0)) (.cse12 (= 1 ~systemActive~0))) (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (not (= ~systemActive~0 0))) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse8 (and (= |timeShift_getWaterLevel_#res#1| 1) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1))) (.cse1 (and .cse4 .cse5 .cse11 .cse10 .cse12)) (.cse9 (= ~pumpRunning~0 0)) (.cse2 (not .cse12)) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse3 (and .cse4 .cse5) .cse6) (or .cse7 .cse3 .cse8 .cse6) (or .cse0 .cse2 (and (<= 1 ~waterLevel~0) (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) (<= 1 |timeShift_getWaterLevel_#res#1|) .cse9) (and .cse4 .cse5 .cse10)) (or (and .cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse3 .cse6) (or .cse7 .cse2 .cse3 .cse8) (or .cse1 (and .cse11 .cse9) .cse2 .cse3 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-17 15:09:17,642 INFO L854 garLoopResultBuilder]: At program point L950(lines 945 953) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))))) [2021-12-17 15:09:17,642 INFO L858 garLoopResultBuilder]: For program point L913(lines 913 917) no Hoare annotation was computed. [2021-12-17 15:09:17,642 INFO L854 garLoopResultBuilder]: At program point L913-2(lines 909 920) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))))) [2021-12-17 15:09:17,642 INFO L858 garLoopResultBuilder]: For program point L146-1(lines 146 152) no Hoare annotation was computed. [2021-12-17 15:09:17,642 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 135 158) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse2 (and .cse0 (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1) (or .cse2 .cse3 (not (= ~systemActive~0 0))) (or (not (= |old(~waterLevel~0)| 1)) .cse2 .cse1 .cse3)))) [2021-12-17 15:09:17,642 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 135 158) no Hoare annotation was computed. [2021-12-17 15:09:17,642 INFO L854 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))))) [2021-12-17 15:09:17,643 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 440) no Hoare annotation was computed. [2021-12-17 15:09:17,643 INFO L854 garLoopResultBuilder]: At program point L229(line 229) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~systemActive~0 0))) (or .cse1 .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))))) [2021-12-17 15:09:17,643 INFO L858 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2021-12-17 15:09:17,643 INFO L858 garLoopResultBuilder]: For program point L85-1(lines 85 91) no Hoare annotation was computed. [2021-12-17 15:09:17,643 INFO L858 garLoopResultBuilder]: For program point L527(lines 527 534) no Hoare annotation was computed. [2021-12-17 15:09:17,643 INFO L854 garLoopResultBuilder]: At program point L366(lines 354 368) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (= ~systemActive~0 0) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,643 INFO L854 garLoopResultBuilder]: At program point L110(lines 65 112) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1)) (.cse2 (= ~pumpRunning~0 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~systemActive~0 0) .cse2) (and .cse0 (<= 1 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:17,643 INFO L854 garLoopResultBuilder]: At program point L77(line 77) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1)) (.cse2 (= ~pumpRunning~0 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~systemActive~0 0) .cse2) (and .cse0 (<= 1 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point L527-2(lines 527 534) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point L358(lines 358 364) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point L358-1(lines 358 364) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L854 garLoopResultBuilder]: At program point L416(lines 412 418) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L861 garLoopResultBuilder]: At program point L536(lines 517 539) the Hoare annotation is: true [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point L66(lines 65 112) no Hoare annotation was computed. [2021-12-17 15:09:17,644 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:09:17,645 INFO L858 garLoopResultBuilder]: For program point L95(lines 95 108) no Hoare annotation was computed. [2021-12-17 15:09:17,645 INFO L854 garLoopResultBuilder]: At program point L504(lines 500 506) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,645 INFO L854 garLoopResultBuilder]: At program point L87(line 87) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1)) (.cse2 (= ~pumpRunning~0 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~systemActive~0 0) .cse2) (and .cse0 (<= 1 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:17,645 INFO L861 garLoopResultBuilder]: At program point L116(lines 55 120) the Hoare annotation is: true [2021-12-17 15:09:17,645 INFO L858 garLoopResultBuilder]: For program point L75(lines 75 81) no Hoare annotation was computed. [2021-12-17 15:09:17,645 INFO L858 garLoopResultBuilder]: For program point L75-1(lines 75 81) no Hoare annotation was computed. [2021-12-17 15:09:17,645 INFO L854 garLoopResultBuilder]: At program point L360(line 360) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) (and .cse0 (= ~systemActive~0 1)))) [2021-12-17 15:09:17,645 INFO L858 garLoopResultBuilder]: For program point L67(lines 67 71) no Hoare annotation was computed. [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point L113(lines 64 114) the Hoare annotation is: false [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point L431(lines 426 434) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point L423(lines 419 425) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,646 INFO L858 garLoopResultBuilder]: For program point L101(lines 101 107) no Hoare annotation was computed. [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point L101-2(lines 95 108) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1)) (.cse2 (= ~pumpRunning~0 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~systemActive~0 0) .cse2) (and .cse0 (<= 1 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:17,646 INFO L861 garLoopResultBuilder]: At program point L514(lines 507 516) the Hoare annotation is: true [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 167 191) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2021-12-17 15:09:17,646 INFO L854 garLoopResultBuilder]: At program point L186(line 186) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0))) [2021-12-17 15:09:17,646 INFO L858 garLoopResultBuilder]: For program point L186-1(lines 167 191) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L854 garLoopResultBuilder]: At program point L331(lines 316 334) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (not (= ~waterLevel~0 1)) .cse0 .cse1) (let ((.cse2 (= ~pumpRunning~0 0))) (or (and (<= 2 ~waterLevel~0) .cse2) (and (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1|)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) .cse2) .cse0 (not (<= 1 ~waterLevel~0)) .cse1)))) [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point L325(lines 325 329) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point L325-2(lines 325 329) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point L990(lines 990 996) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 167 191) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L854 garLoopResultBuilder]: At program point L249(lines 244 251) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= 1 ~systemActive~0)) (not (= |old(~pumpRunning~0)| 0))) [2021-12-17 15:09:17,647 INFO L854 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or (and (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1|)) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (not (= ~waterLevel~0 1)) .cse0 .cse1) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0)) .cse0 (not (<= 1 ~waterLevel~0)) .cse1))) [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point L175(lines 175 183) no Hoare annotation was computed. [2021-12-17 15:09:17,647 INFO L858 garLoopResultBuilder]: For program point L171(lines 171 188) no Hoare annotation was computed. [2021-12-17 15:09:17,648 INFO L854 garLoopResultBuilder]: At program point L995(lines 986 999) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse0) (not (= ~waterLevel~0 1)) .cse1 .cse2) (or .cse1 .cse2 (not (<= 2 ~waterLevel~0)) .cse0))) [2021-12-17 15:09:17,648 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 921 932) no Hoare annotation was computed. [2021-12-17 15:09:17,648 INFO L858 garLoopResultBuilder]: For program point L925-1(lines 921 932) no Hoare annotation was computed. [2021-12-17 15:09:17,648 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 921 932) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~pumpRunning~0 0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1) (or .cse2 .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse2 .cse1 (not (= ~systemActive~0 0))))) [2021-12-17 15:09:17,648 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 193 217) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) [2021-12-17 15:09:17,648 INFO L854 garLoopResultBuilder]: At program point L207(line 207) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2021-12-17 15:09:17,648 INFO L854 garLoopResultBuilder]: At program point L203(line 203) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|)) .cse0 .cse1))) [2021-12-17 15:09:17,648 INFO L858 garLoopResultBuilder]: For program point L201(lines 201 209) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L858 garLoopResultBuilder]: For program point L197(lines 197 214) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L854 garLoopResultBuilder]: At program point L350(lines 335 353) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|))))) [2021-12-17 15:09:17,649 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 193 217) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L858 garLoopResultBuilder]: For program point L344(lines 344 348) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L858 garLoopResultBuilder]: For program point L344-2(lines 344 348) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L854 garLoopResultBuilder]: At program point L212(line 212) the Hoare annotation is: (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2021-12-17 15:09:17,649 INFO L858 garLoopResultBuilder]: For program point L212-1(lines 193 217) no Hoare annotation was computed. [2021-12-17 15:09:17,649 INFO L854 garLoopResultBuilder]: At program point L1005(lines 1000 1008) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|))))) [2021-12-17 15:09:17,652 INFO L732 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:17,653 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:09:17,671 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:09:17 BoogieIcfgContainer [2021-12-17 15:09:17,671 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:09:17,672 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:09:17,672 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:09:17,672 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:09:17,673 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:09" (3/4) ... [2021-12-17 15:09:17,675 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:09:17,679 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-17 15:09:17,681 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:09:17,681 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:09:17,681 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:09:17,682 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:09:17,682 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:09:17,682 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:09:17,682 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:09:17,689 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2021-12-17 15:09:17,690 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:09:17,691 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:09:17,691 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:09:17,691 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:09:17,692 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:17,692 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:17,709 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) [2021-12-17 15:09:17,710 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) && (!(\old(pumpRunning) == 0) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((!(2 <= \old(waterLevel)) || (1 <= waterLevel && pumpRunning == 0)) || !(1 == systemActive)) || 2 <= waterLevel) [2021-12-17 15:09:17,710 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (2 <= \result && waterLevel == \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 2 <= \result) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((waterLevel == \old(waterLevel) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || ((1 <= waterLevel && 1 <= \result) && pumpRunning == 0)) || !(1 == systemActive)) || (2 <= \result && 2 <= waterLevel))) && (((((\result == 1 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:09:17,711 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) [2021-12-17 15:09:17,711 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(2 <= \old(waterLevel)) || ((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 == systemActive)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || (2 <= \result && 2 <= tmp)) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1)) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (((1 <= waterLevel && 1 <= tmp) && 1 <= \result) && pumpRunning == 0)) || ((2 <= \result && 2 <= tmp) && 2 <= waterLevel))) && (((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1))) && ((((((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 == systemActive) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) [2021-12-17 15:09:17,711 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) [2021-12-17 15:09:17,711 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) && ((!(1 == systemActive) || !(1 <= waterLevel)) || (\result == 0 && pumpRunning == \old(pumpRunning))) [2021-12-17 15:09:17,711 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && ((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && (!(2 <= \old(waterLevel)) || !(1 == systemActive)) [2021-12-17 15:09:17,712 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\result == 0) && pumpRunning == 0) || !(waterLevel == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel)) || pumpRunning == 0) [2021-12-17 15:09:17,712 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) && ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((\result == 0 && 1 <= \result) && tmp == 0) && pumpRunning == \old(pumpRunning)) && 1 <= tmp___0)) [2021-12-17 15:09:17,712 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && (!(2 <= \old(waterLevel)) || !(1 == systemActive)) [2021-12-17 15:09:17,714 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\result == 0) || !(waterLevel == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((((2 <= waterLevel && pumpRunning == 0) || (((!(0 == tmp) && \result == 0) && tmp___0 == 0) && pumpRunning == 0)) || !(1 == systemActive)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:09:17,715 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0) [2021-12-17 15:09:17,741 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:09:17,741 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:09:17,742 INFO L158 Benchmark]: Toolchain (without parser) took 9041.77ms. Allocated memory was 94.4MB in the beginning and 163.6MB in the end (delta: 69.2MB). Free memory was 59.7MB in the beginning and 112.3MB in the end (delta: -52.6MB). Peak memory consumption was 15.9MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,742 INFO L158 Benchmark]: CDTParser took 0.10ms. Allocated memory is still 94.4MB. Free memory was 65.8MB in the beginning and 65.8MB in the end (delta: 30.4kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:09:17,742 INFO L158 Benchmark]: CACSL2BoogieTranslator took 343.56ms. Allocated memory is still 94.4MB. Free memory was 59.5MB in the beginning and 62.9MB in the end (delta: -3.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,742 INFO L158 Benchmark]: Boogie Procedure Inliner took 45.39ms. Allocated memory is still 94.4MB. Free memory was 62.9MB in the beginning and 60.5MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,742 INFO L158 Benchmark]: Boogie Preprocessor took 23.82ms. Allocated memory is still 94.4MB. Free memory was 60.5MB in the beginning and 58.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,743 INFO L158 Benchmark]: RCFGBuilder took 413.32ms. Allocated memory is still 94.4MB. Free memory was 58.8MB in the beginning and 42.0MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,743 INFO L158 Benchmark]: TraceAbstraction took 8141.24ms. Allocated memory was 94.4MB in the beginning and 163.6MB in the end (delta: 69.2MB). Free memory was 41.5MB in the beginning and 119.6MB in the end (delta: -78.1MB). Peak memory consumption was 71.0MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,743 INFO L158 Benchmark]: Witness Printer took 69.47ms. Allocated memory is still 163.6MB. Free memory was 119.6MB in the beginning and 112.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:09:17,744 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.10ms. Allocated memory is still 94.4MB. Free memory was 65.8MB in the beginning and 65.8MB in the end (delta: 30.4kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 343.56ms. Allocated memory is still 94.4MB. Free memory was 59.5MB in the beginning and 62.9MB in the end (delta: -3.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 45.39ms. Allocated memory is still 94.4MB. Free memory was 62.9MB in the beginning and 60.5MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 23.82ms. Allocated memory is still 94.4MB. Free memory was 60.5MB in the beginning and 58.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 413.32ms. Allocated memory is still 94.4MB. Free memory was 58.8MB in the beginning and 42.0MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 8141.24ms. Allocated memory was 94.4MB in the beginning and 163.6MB in the end (delta: 69.2MB). Free memory was 41.5MB in the beginning and 119.6MB in the end (delta: -78.1MB). Peak memory consumption was 71.0MB. Max. memory is 16.1GB. * Witness Printer took 69.47ms. Allocated memory is still 163.6MB. Free memory was 119.6MB in the beginning and 112.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 440]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 99 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 8.1s, OverallIterations: 13, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 2.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1957 SdHoareTripleChecker+Valid, 1.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1928 mSDsluCounter, 4676 SdHoareTripleChecker+Invalid, 1.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3103 mSDsCounter, 603 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2100 IncrementalHoareTripleChecker+Invalid, 2703 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 603 mSolverCounterUnsat, 1573 mSDtfsCounter, 2100 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 685 GetRequests, 548 SyntacticMatches, 13 SemanticMatches, 124 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 422 ImplicationChecksByTransitivity, 0.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=714occurred in iteration=12, InterpolantAutomatonStates: 119, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 13 MinimizatonAttempts, 319 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 47 LocationsWithAnnotation, 1948 PreInvPairs, 2074 NumberOfFragments, 1354 HoareAnnotationTreeSize, 1948 FomulaSimplifications, 2645 FormulaSimplificationTreeSizeReduction, 0.4s HoareSimplificationTime, 47 FomulaSimplificationsInter, 10110 FormulaSimplificationTreeSizeReductionInter, 1.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 1.6s InterpolantComputationTime, 1066 NumberOfCodeBlocks, 1066 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 1138 ConstructedInterpolants, 0 QuantifiedInterpolants, 2092 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1579 ConjunctsInSsa, 23 ConjunctsInUnsatCore, 17 InterpolantComputations, 12 PerfectInterpolantSequences, 383/446 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 1000]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) && ((!(1 == systemActive) || !(1 <= waterLevel)) || (\result == 0 && pumpRunning == \old(pumpRunning))) - InvariantResult [Line: 456]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 65]: Loop Invariant Derived loop invariant: (((splverifierCounter == 0 && 2 <= waterLevel) && systemActive == 1) || ((splverifierCounter == 0 && systemActive == 0) && pumpRunning == 0)) || (((splverifierCounter == 0 && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 446]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 986]: Loop Invariant Derived loop invariant: ((((!(\result == 0) && pumpRunning == 0) || !(waterLevel == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel)) || pumpRunning == 0) - InvariantResult [Line: 372]: Loop Invariant Derived loop invariant: ((((((((!(2 <= \old(waterLevel)) || ((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 == systemActive)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || (2 <= \result && 2 <= tmp)) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1)) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (((1 <= waterLevel && 1 <= tmp) && 1 <= \result) && pumpRunning == 0)) || ((2 <= \result && 2 <= tmp) && 2 <= waterLevel))) && (((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (\result == 1 && tmp == 1))) && ((((((((2 <= \result && 2 <= tmp) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 == systemActive) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 354]: Loop Invariant Derived loop invariant: (splverifierCounter == 0 && systemActive == 0) && pumpRunning == 0 - InvariantResult [Line: 500]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: (((((((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (2 <= \result && waterLevel == \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 2 <= \result) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((waterLevel == \old(waterLevel) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || ((1 <= waterLevel && 1 <= \result) && pumpRunning == 0)) || !(1 == systemActive)) || (2 <= \result && 2 <= waterLevel))) && (((((\result == 1 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: (((!(\result == 0) || !(waterLevel == 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((((2 <= waterLevel && pumpRunning == 0) || (((!(0 == tmp) && \result == 0) && tmp___0 == 0) && pumpRunning == 0)) || !(1 == systemActive)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 507]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 436]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && (!(2 <= \old(waterLevel)) || !(1 == systemActive)) - InvariantResult [Line: 945]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) - InvariantResult [Line: 335]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) && ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((\result == 0 && 1 <= \result) && tmp == 0) && pumpRunning == \old(pumpRunning)) && 1 <= tmp___0)) - InvariantResult [Line: 412]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 271]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && ((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && (!(2 <= \old(waterLevel)) || !(1 == systemActive)) - InvariantResult [Line: 260]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) - InvariantResult [Line: 909]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 0)) && ((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) - InvariantResult [Line: 244]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0) - InvariantResult [Line: 426]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 55]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 219]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || !(1 == systemActive)) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) && (!(\old(pumpRunning) == 0) || !(systemActive == 0))) && (((!(\old(waterLevel) == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((!(2 <= \old(waterLevel)) || (1 <= waterLevel && pumpRunning == 0)) || !(1 == systemActive)) || 2 <= waterLevel) - InvariantResult [Line: 517]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:09:17,808 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE