./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 603cfb64133b588a2e9c81e31ac984484d295feb0a468539180131e3ac5a47d6 --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:09:40,631 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:09:40,632 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:09:40,703 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:09:40,703 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:09:40,704 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:09:40,705 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:09:40,711 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:09:40,712 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:09:40,713 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:09:40,713 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:09:40,714 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:09:40,714 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:09:40,714 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:09:40,715 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:09:40,716 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:09:40,717 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:09:40,717 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:09:40,718 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:09:40,719 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:09:40,720 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:09:40,726 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:09:40,728 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:09:40,729 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:09:40,732 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:09:40,734 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:09:40,734 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:09:40,736 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:09:40,736 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:09:40,737 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:09:40,738 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:09:40,738 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:09:40,739 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:09:40,740 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:09:40,741 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:09:40,741 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:09:40,742 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:09:40,742 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:09:40,742 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:09:40,743 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:09:40,743 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:09:40,744 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:09:40,765 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:09:40,766 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:09:40,766 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:09:40,766 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:09:40,767 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:09:40,767 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:09:40,767 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:09:40,768 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:09:40,768 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:09:40,768 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:09:40,769 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:09:40,770 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:09:40,770 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:40,771 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:09:40,771 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:09:40,772 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:09:40,772 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:09:40,772 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:09:40,772 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 603cfb64133b588a2e9c81e31ac984484d295feb0a468539180131e3ac5a47d6 [2021-12-17 15:09:40,956 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:09:40,979 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:09:40,981 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:09:40,982 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:09:40,983 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:09:40,984 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c [2021-12-17 15:09:41,036 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/837bcdcf1/fad16b4ed69643d299db59d3c5074590/FLAGcfd7aa86c [2021-12-17 15:09:41,489 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:09:41,491 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c [2021-12-17 15:09:41,500 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/837bcdcf1/fad16b4ed69643d299db59d3c5074590/FLAGcfd7aa86c [2021-12-17 15:09:41,880 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/837bcdcf1/fad16b4ed69643d299db59d3c5074590 [2021-12-17 15:09:41,889 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:09:41,893 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:09:41,896 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:41,896 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:09:41,917 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:09:41,918 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:41" (1/1) ... [2021-12-17 15:09:41,919 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@47407284 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:41, skipping insertion in model container [2021-12-17 15:09:41,919 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:09:41" (1/1) ... [2021-12-17 15:09:41,924 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:09:42,007 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:09:42,238 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c[3064,3077] [2021-12-17 15:09:42,350 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:42,361 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:09:42,392 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product45.cil.c[3064,3077] [2021-12-17 15:09:42,433 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:09:42,464 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:09:42,465 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42 WrapperNode [2021-12-17 15:09:42,465 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:09:42,466 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:42,466 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:09:42,466 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:09:42,472 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,487 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,516 INFO L137 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 264 [2021-12-17 15:09:42,516 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:09:42,517 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:09:42,517 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:09:42,517 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:09:42,526 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,526 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,533 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,533 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,537 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,554 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,555 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,557 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:09:42,557 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:09:42,558 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:09:42,558 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:09:42,561 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (1/1) ... [2021-12-17 15:09:42,566 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:09:42,573 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:42,584 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:09:42,589 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:09:42,624 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:09:42,625 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:09:42,625 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:09:42,625 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:09:42,625 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:09:42,625 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:09:42,625 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:09:42,625 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:09:42,626 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:09:42,626 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:09:42,626 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:09:42,626 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2021-12-17 15:09:42,626 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2021-12-17 15:09:42,626 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-17 15:09:42,626 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-17 15:09:42,627 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:09:42,627 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:09:42,627 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:09:42,627 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:09:42,627 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:09:42,680 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:09:42,692 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:09:42,982 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:09:42,988 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:09:42,988 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:09:42,989 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:42 BoogieIcfgContainer [2021-12-17 15:09:42,989 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:09:42,991 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:09:42,991 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:09:42,993 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:09:42,993 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:09:41" (1/3) ... [2021-12-17 15:09:42,994 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@4d2cbe2b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:42, skipping insertion in model container [2021-12-17 15:09:42,994 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:09:42" (2/3) ... [2021-12-17 15:09:42,994 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@4d2cbe2b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:09:42, skipping insertion in model container [2021-12-17 15:09:42,994 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:42" (3/3) ... [2021-12-17 15:09:42,995 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product45.cil.c [2021-12-17 15:09:42,999 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:09:42,999 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:09:43,038 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:09:43,045 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:09:43,045 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:09:43,070 INFO L276 IsEmpty]: Start isEmpty. Operand has 98 states, 74 states have (on average 1.364864864864865) internal successors, (101), 82 states have internal predecessors, (101), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) [2021-12-17 15:09:43,077 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-17 15:09:43,078 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:43,078 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:43,079 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:43,083 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:43,083 INFO L85 PathProgramCache]: Analyzing trace with hash -1310639887, now seen corresponding path program 1 times [2021-12-17 15:09:43,089 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:43,089 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1150602481] [2021-12-17 15:09:43,090 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:43,090 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:43,209 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,254 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-17 15:09:43,256 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,260 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:09:43,261 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,267 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:43,267 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:43,267 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1150602481] [2021-12-17 15:09:43,268 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1150602481] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:43,268 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:43,269 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:09:43,270 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [990739070] [2021-12-17 15:09:43,270 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:43,274 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:09:43,275 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:43,298 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:09:43,299 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:43,302 INFO L87 Difference]: Start difference. First operand has 98 states, 74 states have (on average 1.364864864864865) internal successors, (101), 82 states have internal predecessors, (101), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:43,343 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:43,344 INFO L93 Difference]: Finished difference Result 187 states and 252 transitions. [2021-12-17 15:09:43,344 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:09:43,345 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2021-12-17 15:09:43,346 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:43,353 INFO L225 Difference]: With dead ends: 187 [2021-12-17 15:09:43,354 INFO L226 Difference]: Without dead ends: 89 [2021-12-17 15:09:43,357 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:09:43,361 INFO L933 BasicCegarLoop]: 123 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 123 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:43,361 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 123 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:43,373 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2021-12-17 15:09:43,394 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 89. [2021-12-17 15:09:43,395 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 89 states, 67 states have (on average 1.2985074626865671) internal successors, (87), 74 states have internal predecessors, (87), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 11 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-17 15:09:43,396 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 89 states to 89 states and 114 transitions. [2021-12-17 15:09:43,397 INFO L78 Accepts]: Start accepts. Automaton has 89 states and 114 transitions. Word has length 32 [2021-12-17 15:09:43,397 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:43,397 INFO L470 AbstractCegarLoop]: Abstraction has 89 states and 114 transitions. [2021-12-17 15:09:43,397 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:43,398 INFO L276 IsEmpty]: Start isEmpty. Operand 89 states and 114 transitions. [2021-12-17 15:09:43,400 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2021-12-17 15:09:43,400 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:43,400 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:43,400 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:09:43,400 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:43,401 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:43,401 INFO L85 PathProgramCache]: Analyzing trace with hash -527547429, now seen corresponding path program 1 times [2021-12-17 15:09:43,402 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:43,402 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1868279540] [2021-12-17 15:09:43,402 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:43,402 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:43,423 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,451 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:09:43,453 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,455 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:09:43,456 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,458 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:43,458 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:43,459 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1868279540] [2021-12-17 15:09:43,459 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1868279540] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:43,459 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:43,459 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:09:43,459 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2140690916] [2021-12-17 15:09:43,459 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:43,460 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:43,460 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:43,461 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:43,461 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:43,461 INFO L87 Difference]: Start difference. First operand 89 states and 114 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:43,472 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:43,472 INFO L93 Difference]: Finished difference Result 143 states and 183 transitions. [2021-12-17 15:09:43,472 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:43,472 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2021-12-17 15:09:43,473 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:43,474 INFO L225 Difference]: With dead ends: 143 [2021-12-17 15:09:43,474 INFO L226 Difference]: Without dead ends: 80 [2021-12-17 15:09:43,474 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:43,476 INFO L933 BasicCegarLoop]: 101 mSDtfsCounter, 12 mSDsluCounter, 85 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 186 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:43,477 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 186 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:43,477 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2021-12-17 15:09:43,482 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 80. [2021-12-17 15:09:43,485 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 61 states have (on average 1.3114754098360655) internal successors, (80), 68 states have internal predecessors, (80), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-17 15:09:43,486 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 102 transitions. [2021-12-17 15:09:43,486 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 102 transitions. Word has length 33 [2021-12-17 15:09:43,486 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:43,486 INFO L470 AbstractCegarLoop]: Abstraction has 80 states and 102 transitions. [2021-12-17 15:09:43,486 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:09:43,486 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 102 transitions. [2021-12-17 15:09:43,487 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2021-12-17 15:09:43,487 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:43,488 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:43,488 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:09:43,488 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:43,488 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:43,488 INFO L85 PathProgramCache]: Analyzing trace with hash 671106305, now seen corresponding path program 1 times [2021-12-17 15:09:43,489 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:43,489 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1786321716] [2021-12-17 15:09:43,489 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:43,489 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:43,513 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,578 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:43,582 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:09:43,592 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,598 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:43,598 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:43,599 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1786321716] [2021-12-17 15:09:43,599 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1786321716] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:43,599 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:43,599 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:09:43,600 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1331218338] [2021-12-17 15:09:43,600 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:43,600 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:09:43,600 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:43,601 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:09:43,601 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:43,601 INFO L87 Difference]: Start difference. First operand 80 states and 102 transitions. Second operand has 3 states, 3 states have (on average 10.0) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:43,619 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:43,624 INFO L93 Difference]: Finished difference Result 152 states and 197 transitions. [2021-12-17 15:09:43,624 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:09:43,624 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.0) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 37 [2021-12-17 15:09:43,625 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:43,625 INFO L225 Difference]: With dead ends: 152 [2021-12-17 15:09:43,626 INFO L226 Difference]: Without dead ends: 80 [2021-12-17 15:09:43,649 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:09:43,650 INFO L933 BasicCegarLoop]: 100 mSDtfsCounter, 79 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 79 SdHoareTripleChecker+Valid, 100 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:43,650 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [79 Valid, 100 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:09:43,651 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2021-12-17 15:09:43,658 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 80. [2021-12-17 15:09:43,659 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-17 15:09:43,659 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 101 transitions. [2021-12-17 15:09:43,659 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 101 transitions. Word has length 37 [2021-12-17 15:09:43,660 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:43,661 INFO L470 AbstractCegarLoop]: Abstraction has 80 states and 101 transitions. [2021-12-17 15:09:43,661 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 10.0) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:09:43,661 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 101 transitions. [2021-12-17 15:09:43,662 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:09:43,662 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:43,662 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:43,662 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:09:43,662 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:43,663 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:43,663 INFO L85 PathProgramCache]: Analyzing trace with hash -488472773, now seen corresponding path program 1 times [2021-12-17 15:09:43,663 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:43,663 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1854198057] [2021-12-17 15:09:43,663 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:43,664 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:43,678 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,705 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:43,707 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,712 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:09:43,713 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:43,725 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,727 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-17 15:09:43,735 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,738 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:43,738 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:43,738 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1854198057] [2021-12-17 15:09:43,738 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1854198057] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:43,738 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:43,739 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:43,739 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2129812880] [2021-12-17 15:09:43,739 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:43,739 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:43,739 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:43,740 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:43,740 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:43,740 INFO L87 Difference]: Start difference. First operand 80 states and 101 transitions. Second operand has 5 states, 5 states have (on average 7.2) internal successors, (36), 5 states have internal predecessors, (36), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:43,878 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:43,879 INFO L93 Difference]: Finished difference Result 235 states and 297 transitions. [2021-12-17 15:09:43,879 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:43,879 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.2) internal successors, (36), 5 states have internal predecessors, (36), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 47 [2021-12-17 15:09:43,880 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:43,880 INFO L225 Difference]: With dead ends: 235 [2021-12-17 15:09:43,881 INFO L226 Difference]: Without dead ends: 163 [2021-12-17 15:09:43,881 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 10 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:43,882 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 187 mSDsluCounter, 175 mSDsCounter, 0 mSdLazyCounter, 101 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 190 SdHoareTripleChecker+Valid, 306 SdHoareTripleChecker+Invalid, 155 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 101 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:43,883 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [190 Valid, 306 Invalid, 155 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:43,883 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 163 states. [2021-12-17 15:09:43,900 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 163 to 157. [2021-12-17 15:09:43,900 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 157 states, 120 states have (on average 1.2583333333333333) internal successors, (151), 128 states have internal predecessors, (151), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-17 15:09:43,901 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 157 states to 157 states and 192 transitions. [2021-12-17 15:09:43,901 INFO L78 Accepts]: Start accepts. Automaton has 157 states and 192 transitions. Word has length 47 [2021-12-17 15:09:43,901 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:43,902 INFO L470 AbstractCegarLoop]: Abstraction has 157 states and 192 transitions. [2021-12-17 15:09:43,902 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.2) internal successors, (36), 5 states have internal predecessors, (36), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:43,902 INFO L276 IsEmpty]: Start isEmpty. Operand 157 states and 192 transitions. [2021-12-17 15:09:43,903 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 54 [2021-12-17 15:09:43,903 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:43,903 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:43,903 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:09:43,904 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:43,904 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:43,904 INFO L85 PathProgramCache]: Analyzing trace with hash 1464828133, now seen corresponding path program 1 times [2021-12-17 15:09:43,904 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:43,904 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1684318370] [2021-12-17 15:09:43,905 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:43,905 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:43,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,927 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:43,928 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,931 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:09:43,933 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,944 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:43,945 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,947 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-17 15:09:43,948 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:43,949 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:43,950 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:43,950 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1684318370] [2021-12-17 15:09:43,951 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1684318370] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:43,951 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:43,951 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:43,951 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1011915868] [2021-12-17 15:09:43,951 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:43,952 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:43,952 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:43,952 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:43,952 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:43,953 INFO L87 Difference]: Start difference. First operand 157 states and 192 transitions. Second operand has 5 states, 5 states have (on average 8.4) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:09:44,062 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:44,063 INFO L93 Difference]: Finished difference Result 324 states and 404 transitions. [2021-12-17 15:09:44,063 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-17 15:09:44,063 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.4) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 53 [2021-12-17 15:09:44,065 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:44,070 INFO L225 Difference]: With dead ends: 324 [2021-12-17 15:09:44,070 INFO L226 Difference]: Without dead ends: 175 [2021-12-17 15:09:44,073 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:09:44,075 INFO L933 BasicCegarLoop]: 92 mSDtfsCounter, 90 mSDsluCounter, 195 mSDsCounter, 0 mSdLazyCounter, 87 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 96 SdHoareTripleChecker+Valid, 287 SdHoareTripleChecker+Invalid, 108 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 87 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:44,077 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [96 Valid, 287 Invalid, 108 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 87 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:44,079 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2021-12-17 15:09:44,091 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 159. [2021-12-17 15:09:44,091 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 159 states, 122 states have (on average 1.2540983606557377) internal successors, (153), 130 states have internal predecessors, (153), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-17 15:09:44,092 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 159 states to 159 states and 194 transitions. [2021-12-17 15:09:44,092 INFO L78 Accepts]: Start accepts. Automaton has 159 states and 194 transitions. Word has length 53 [2021-12-17 15:09:44,093 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:44,093 INFO L470 AbstractCegarLoop]: Abstraction has 159 states and 194 transitions. [2021-12-17 15:09:44,093 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.4) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:09:44,093 INFO L276 IsEmpty]: Start isEmpty. Operand 159 states and 194 transitions. [2021-12-17 15:09:44,094 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 54 [2021-12-17 15:09:44,094 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:44,094 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:44,095 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:09:44,095 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:44,095 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:44,095 INFO L85 PathProgramCache]: Analyzing trace with hash 1042126307, now seen corresponding path program 1 times [2021-12-17 15:09:44,095 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:44,096 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1223538097] [2021-12-17 15:09:44,096 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:44,096 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:44,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,135 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:44,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,143 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:09:44,146 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,166 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:44,167 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,171 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-17 15:09:44,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,180 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-17 15:09:44,181 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:44,181 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1223538097] [2021-12-17 15:09:44,181 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1223538097] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:44,182 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:44,182 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:09:44,182 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [109802826] [2021-12-17 15:09:44,183 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:44,183 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:09:44,184 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:44,184 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:09:44,185 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:44,185 INFO L87 Difference]: Start difference. First operand 159 states and 194 transitions. Second operand has 7 states, 7 states have (on average 6.285714285714286) internal successors, (44), 5 states have internal predecessors, (44), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:09:44,371 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:44,372 INFO L93 Difference]: Finished difference Result 322 states and 394 transitions. [2021-12-17 15:09:44,372 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-17 15:09:44,372 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.285714285714286) internal successors, (44), 5 states have internal predecessors, (44), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) Word has length 53 [2021-12-17 15:09:44,373 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:44,375 INFO L225 Difference]: With dead ends: 322 [2021-12-17 15:09:44,375 INFO L226 Difference]: Without dead ends: 171 [2021-12-17 15:09:44,376 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:09:44,383 INFO L933 BasicCegarLoop]: 101 mSDtfsCounter, 120 mSDsluCounter, 348 mSDsCounter, 0 mSdLazyCounter, 205 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 127 SdHoareTripleChecker+Valid, 449 SdHoareTripleChecker+Invalid, 240 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 205 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:44,385 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [127 Valid, 449 Invalid, 240 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 205 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:44,386 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 171 states. [2021-12-17 15:09:44,396 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 171 to 157. [2021-12-17 15:09:44,399 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 157 states, 120 states have (on average 1.225) internal successors, (147), 128 states have internal predecessors, (147), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-17 15:09:44,400 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 157 states to 157 states and 188 transitions. [2021-12-17 15:09:44,400 INFO L78 Accepts]: Start accepts. Automaton has 157 states and 188 transitions. Word has length 53 [2021-12-17 15:09:44,400 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:44,401 INFO L470 AbstractCegarLoop]: Abstraction has 157 states and 188 transitions. [2021-12-17 15:09:44,401 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.285714285714286) internal successors, (44), 5 states have internal predecessors, (44), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:09:44,401 INFO L276 IsEmpty]: Start isEmpty. Operand 157 states and 188 transitions. [2021-12-17 15:09:44,402 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-17 15:09:44,402 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:44,402 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:44,402 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:09:44,402 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:44,403 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:44,403 INFO L85 PathProgramCache]: Analyzing trace with hash -2072494715, now seen corresponding path program 1 times [2021-12-17 15:09:44,403 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:44,403 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [943142517] [2021-12-17 15:09:44,403 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:44,403 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:44,413 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:44,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,429 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:09:44,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,447 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:44,449 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,451 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-17 15:09:44,452 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,453 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:44,454 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:44,454 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [943142517] [2021-12-17 15:09:44,454 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [943142517] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:44,454 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:44,454 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:09:44,454 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [60140575] [2021-12-17 15:09:44,454 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:44,455 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:09:44,455 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:44,455 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:09:44,455 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:09:44,456 INFO L87 Difference]: Start difference. First operand 157 states and 188 transitions. Second operand has 6 states, 6 states have (on average 8.0) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:09:44,546 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:44,546 INFO L93 Difference]: Finished difference Result 316 states and 385 transitions. [2021-12-17 15:09:44,547 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:44,547 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 59 [2021-12-17 15:09:44,547 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:44,548 INFO L225 Difference]: With dead ends: 316 [2021-12-17 15:09:44,548 INFO L226 Difference]: Without dead ends: 167 [2021-12-17 15:09:44,549 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:09:44,549 INFO L933 BasicCegarLoop]: 90 mSDtfsCounter, 69 mSDsluCounter, 273 mSDsCounter, 0 mSdLazyCounter, 112 mSolverCounterSat, 23 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 74 SdHoareTripleChecker+Valid, 363 SdHoareTripleChecker+Invalid, 135 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 23 IncrementalHoareTripleChecker+Valid, 112 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:44,550 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [74 Valid, 363 Invalid, 135 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [23 Valid, 112 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:44,550 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 167 states. [2021-12-17 15:09:44,558 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 167 to 160. [2021-12-17 15:09:44,559 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 160 states, 123 states have (on average 1.2195121951219512) internal successors, (150), 131 states have internal predecessors, (150), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-17 15:09:44,559 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 160 states to 160 states and 191 transitions. [2021-12-17 15:09:44,560 INFO L78 Accepts]: Start accepts. Automaton has 160 states and 191 transitions. Word has length 59 [2021-12-17 15:09:44,560 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:44,560 INFO L470 AbstractCegarLoop]: Abstraction has 160 states and 191 transitions. [2021-12-17 15:09:44,560 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:09:44,560 INFO L276 IsEmpty]: Start isEmpty. Operand 160 states and 191 transitions. [2021-12-17 15:09:44,561 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-17 15:09:44,561 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:44,561 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:44,561 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:09:44,562 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:44,562 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:44,562 INFO L85 PathProgramCache]: Analyzing trace with hash 1236936713, now seen corresponding path program 1 times [2021-12-17 15:09:44,562 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:44,562 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [975987884] [2021-12-17 15:09:44,562 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:44,563 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:44,571 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:09:44,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,596 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:09:44,599 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,608 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:44,609 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,621 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-17 15:09:44,621 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,623 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:44,623 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:44,623 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [975987884] [2021-12-17 15:09:44,623 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [975987884] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:44,623 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:44,623 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:09:44,624 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1051968966] [2021-12-17 15:09:44,624 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:44,624 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:09:44,624 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:44,624 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:09:44,624 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:09:44,624 INFO L87 Difference]: Start difference. First operand 160 states and 191 transitions. Second operand has 5 states, 5 states have (on average 9.6) internal successors, (48), 4 states have internal predecessors, (48), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:44,772 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:44,772 INFO L93 Difference]: Finished difference Result 441 states and 552 transitions. [2021-12-17 15:09:44,772 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:09:44,772 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 9.6) internal successors, (48), 4 states have internal predecessors, (48), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 59 [2021-12-17 15:09:44,773 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:44,774 INFO L225 Difference]: With dead ends: 441 [2021-12-17 15:09:44,774 INFO L226 Difference]: Without dead ends: 289 [2021-12-17 15:09:44,775 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:09:44,775 INFO L933 BasicCegarLoop]: 140 mSDtfsCounter, 215 mSDsluCounter, 167 mSDsCounter, 0 mSdLazyCounter, 147 mSolverCounterSat, 68 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 223 SdHoareTripleChecker+Valid, 307 SdHoareTripleChecker+Invalid, 215 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 68 IncrementalHoareTripleChecker+Valid, 147 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:44,776 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [223 Valid, 307 Invalid, 215 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [68 Valid, 147 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:09:44,776 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 289 states. [2021-12-17 15:09:44,787 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 289 to 287. [2021-12-17 15:09:44,788 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 287 states, 218 states have (on average 1.2064220183486238) internal successors, (263), 230 states have internal predecessors, (263), 36 states have call successors, (36), 31 states have call predecessors, (36), 32 states have return successors, (51), 36 states have call predecessors, (51), 36 states have call successors, (51) [2021-12-17 15:09:44,789 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 287 states to 287 states and 350 transitions. [2021-12-17 15:09:44,789 INFO L78 Accepts]: Start accepts. Automaton has 287 states and 350 transitions. Word has length 59 [2021-12-17 15:09:44,789 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:44,789 INFO L470 AbstractCegarLoop]: Abstraction has 287 states and 350 transitions. [2021-12-17 15:09:44,790 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 9.6) internal successors, (48), 4 states have internal predecessors, (48), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-17 15:09:44,790 INFO L276 IsEmpty]: Start isEmpty. Operand 287 states and 350 transitions. [2021-12-17 15:09:44,790 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2021-12-17 15:09:44,790 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:44,791 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:44,791 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:09:44,791 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:44,791 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:44,791 INFO L85 PathProgramCache]: Analyzing trace with hash -1533447185, now seen corresponding path program 1 times [2021-12-17 15:09:44,792 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:44,792 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [646130927] [2021-12-17 15:09:44,792 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:44,792 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:44,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,867 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:09:44,869 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2021-12-17 15:09:44,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,878 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2021-12-17 15:09:44,880 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,890 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:44,891 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,893 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2021-12-17 15:09:44,893 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:44,895 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:09:44,895 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:44,895 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [646130927] [2021-12-17 15:09:44,895 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [646130927] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:09:44,895 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:09:44,895 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2021-12-17 15:09:44,895 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [352527007] [2021-12-17 15:09:44,896 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:09:44,896 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2021-12-17 15:09:44,896 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:44,896 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2021-12-17 15:09:44,896 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:09:44,897 INFO L87 Difference]: Start difference. First operand 287 states and 350 transitions. Second operand has 10 states, 10 states have (on average 5.0) internal successors, (50), 8 states have internal predecessors, (50), 4 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-17 15:09:45,377 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:45,378 INFO L93 Difference]: Finished difference Result 736 states and 932 transitions. [2021-12-17 15:09:45,378 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 24 states. [2021-12-17 15:09:45,378 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 5.0) internal successors, (50), 8 states have internal predecessors, (50), 4 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) Word has length 63 [2021-12-17 15:09:45,379 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:45,381 INFO L225 Difference]: With dead ends: 736 [2021-12-17 15:09:45,381 INFO L226 Difference]: Without dead ends: 507 [2021-12-17 15:09:45,382 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 40 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 179 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=201, Invalid=611, Unknown=0, NotChecked=0, Total=812 [2021-12-17 15:09:45,382 INFO L933 BasicCegarLoop]: 137 mSDtfsCounter, 508 mSDsluCounter, 456 mSDsCounter, 0 mSdLazyCounter, 536 mSolverCounterSat, 177 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 513 SdHoareTripleChecker+Valid, 593 SdHoareTripleChecker+Invalid, 713 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 177 IncrementalHoareTripleChecker+Valid, 536 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:45,382 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [513 Valid, 593 Invalid, 713 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [177 Valid, 536 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:09:45,383 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 507 states. [2021-12-17 15:09:45,402 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 507 to 429. [2021-12-17 15:09:45,403 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 429 states, 326 states have (on average 1.1932515337423313) internal successors, (389), 345 states have internal predecessors, (389), 53 states have call successors, (53), 44 states have call predecessors, (53), 49 states have return successors, (72), 52 states have call predecessors, (72), 53 states have call successors, (72) [2021-12-17 15:09:45,405 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 429 states to 429 states and 514 transitions. [2021-12-17 15:09:45,405 INFO L78 Accepts]: Start accepts. Automaton has 429 states and 514 transitions. Word has length 63 [2021-12-17 15:09:45,406 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:45,406 INFO L470 AbstractCegarLoop]: Abstraction has 429 states and 514 transitions. [2021-12-17 15:09:45,406 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 5.0) internal successors, (50), 8 states have internal predecessors, (50), 4 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-17 15:09:45,406 INFO L276 IsEmpty]: Start isEmpty. Operand 429 states and 514 transitions. [2021-12-17 15:09:45,407 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 107 [2021-12-17 15:09:45,408 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:09:45,408 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:45,409 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:09:45,409 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:09:45,409 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:09:45,410 INFO L85 PathProgramCache]: Analyzing trace with hash -706462267, now seen corresponding path program 1 times [2021-12-17 15:09:45,410 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:09:45,410 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1122651942] [2021-12-17 15:09:45,410 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:45,411 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:09:45,427 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,510 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:09:45,513 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,523 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:09:45,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,540 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:09:45,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-17 15:09:45,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,559 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:09:45,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,562 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2021-12-17 15:09:45,563 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,571 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2021-12-17 15:09:45,572 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,574 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2021-12-17 15:09:45,575 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,577 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:09:45,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,579 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2021-12-17 15:09:45,583 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,585 INFO L134 CoverageAnalysis]: Checked inductivity of 37 backedges. 8 proven. 18 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-17 15:09:45,585 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:09:45,586 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1122651942] [2021-12-17 15:09:45,586 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1122651942] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:09:45,586 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1358076303] [2021-12-17 15:09:45,586 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:09:45,586 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:09:45,586 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:09:45,588 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:09:45,626 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:09:45,685 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:09:45,688 INFO L263 TraceCheckSpWp]: Trace formula consists of 495 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-17 15:09:45,711 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:09:45,919 INFO L134 CoverageAnalysis]: Checked inductivity of 37 backedges. 28 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:09:45,919 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:09:46,159 INFO L134 CoverageAnalysis]: Checked inductivity of 37 backedges. 18 proven. 8 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-17 15:09:46,159 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1358076303] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:09:46,159 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:09:46,160 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 15 [2021-12-17 15:09:46,160 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1548882817] [2021-12-17 15:09:46,160 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:09:46,160 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2021-12-17 15:09:46,161 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:09:46,161 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2021-12-17 15:09:46,161 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=36, Invalid=174, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:09:46,161 INFO L87 Difference]: Start difference. First operand 429 states and 514 transitions. Second operand has 15 states, 15 states have (on average 9.066666666666666) internal successors, (136), 10 states have internal predecessors, (136), 6 states have call successors, (24), 7 states have call predecessors, (24), 6 states have return successors, (21), 8 states have call predecessors, (21), 6 states have call successors, (21) [2021-12-17 15:09:47,026 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:09:47,027 INFO L93 Difference]: Finished difference Result 897 states and 1098 transitions. [2021-12-17 15:09:47,027 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2021-12-17 15:09:47,028 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 15 states have (on average 9.066666666666666) internal successors, (136), 10 states have internal predecessors, (136), 6 states have call successors, (24), 7 states have call predecessors, (24), 6 states have return successors, (21), 8 states have call predecessors, (21), 6 states have call successors, (21) Word has length 106 [2021-12-17 15:09:47,029 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:09:47,030 INFO L225 Difference]: With dead ends: 897 [2021-12-17 15:09:47,030 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:09:47,033 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 275 GetRequests, 237 SyntacticMatches, 1 SemanticMatches, 37 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 324 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=342, Invalid=1140, Unknown=0, NotChecked=0, Total=1482 [2021-12-17 15:09:47,035 INFO L933 BasicCegarLoop]: 211 mSDtfsCounter, 382 mSDsluCounter, 1032 mSDsCounter, 0 mSdLazyCounter, 1063 mSolverCounterSat, 184 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 385 SdHoareTripleChecker+Valid, 1243 SdHoareTripleChecker+Invalid, 1247 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 184 IncrementalHoareTripleChecker+Valid, 1063 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2021-12-17 15:09:47,036 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [385 Valid, 1243 Invalid, 1247 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [184 Valid, 1063 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2021-12-17 15:09:47,036 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:09:47,036 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:09:47,036 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:09:47,037 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:09:47,037 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 106 [2021-12-17 15:09:47,037 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:09:47,038 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:09:47,038 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 15 states, 15 states have (on average 9.066666666666666) internal successors, (136), 10 states have internal predecessors, (136), 6 states have call successors, (24), 7 states have call predecessors, (24), 6 states have return successors, (21), 8 states have call predecessors, (21), 6 states have call successors, (21) [2021-12-17 15:09:47,038 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:09:47,038 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:09:47,042 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:09:47,089 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:09:47,260 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-17 15:09:47,262 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:09:50,419 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 610 616) no Hoare annotation was computed. [2021-12-17 15:09:50,419 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 610 616) the Hoare annotation is: true [2021-12-17 15:09:50,419 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 83 94) the Hoare annotation is: true [2021-12-17 15:09:50,419 INFO L858 garLoopResultBuilder]: For program point L87-1(lines 83 94) no Hoare annotation was computed. [2021-12-17 15:09:50,419 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 83 94) no Hoare annotation was computed. [2021-12-17 15:09:50,419 INFO L858 garLoopResultBuilder]: For program point L897(lines 897 901) no Hoare annotation was computed. [2021-12-17 15:09:50,419 INFO L861 garLoopResultBuilder]: At program point L897-1(lines 897 901) the Hoare annotation is: true [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 883 912) no Hoare annotation was computed. [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point L894(line 894) no Hoare annotation was computed. [2021-12-17 15:09:50,420 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 883 912) the Hoare annotation is: true [2021-12-17 15:09:50,420 INFO L861 garLoopResultBuilder]: At program point L893-2(lines 893 907) the Hoare annotation is: true [2021-12-17 15:09:50,420 INFO L861 garLoopResultBuilder]: At program point L889(line 889) the Hoare annotation is: true [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point L889-1(line 889) no Hoare annotation was computed. [2021-12-17 15:09:50,420 INFO L861 garLoopResultBuilder]: At program point L908(lines 883 912) the Hoare annotation is: true [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point L904(line 904) no Hoare annotation was computed. [2021-12-17 15:09:50,420 INFO L854 garLoopResultBuilder]: At program point L543(lines 536 545) the Hoare annotation is: (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (and (<= 1 ~switchedOnBeforeTS~0) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (and .cse1 (= ~pumpRunning~0 0)) .cse2 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 .cse3 .cse4) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2 .cse3 .cse4)))) [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point L155(line 155) no Hoare annotation was computed. [2021-12-17 15:09:50,420 INFO L854 garLoopResultBuilder]: At program point L663(line 663) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 .cse2) (or .cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) .cse1 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:09:50,420 INFO L854 garLoopResultBuilder]: At program point L663-1(lines 644 668) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse4 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (not (<= 1 |old(~pumpRunning~0)|)))) (and (let ((.cse3 (= ~waterLevel~0 1))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 .cse3 .cse4) (and .cse2 .cse3 .cse5) .cse6)) (let ((.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse7 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse0 (and .cse7 .cse5) .cse1 (not (= |old(~pumpRunning~0)| 0)))) (let ((.cse8 (<= ~waterLevel~0 2))) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 (and .cse2 .cse4 .cse8) (and .cse2 .cse8 .cse5) .cse6)))) [2021-12-17 15:09:50,420 INFO L858 garLoopResultBuilder]: For program point L597-1(lines 597 603) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L854 garLoopResultBuilder]: At program point L556(line 556) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= ~pumpRunning~0 0)) (.cse7 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (= 1 ~systemActive~0))) (.cse8 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse4 (= ~waterLevel~0 1))) (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5) (and .cse3 .cse4 .cse6) .cse7)) (or .cse1 (and (= ~waterLevel~0 |old(~waterLevel~0)|) .cse6) .cse2 .cse8) (let ((.cse9 (<= ~waterLevel~0 2))) (or .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2 (and .cse3 .cse5 .cse9) (and .cse3 .cse9 .cse6) .cse7)) (or .cse0 .cse1 .cse2 .cse8))) [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L556-1(line 556) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 583 609) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L854 garLoopResultBuilder]: At program point L156(lines 151 158) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L590(lines 590 596) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L590-2(lines 586 608) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L652(lines 652 660) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L648(lines 648 665) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L854 garLoopResultBuilder]: At program point L132(lines 127 135) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (= 1 ~systemActive~0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= ~pumpRunning~0 0)) (.cse7 (not (<= 1 |old(~pumpRunning~0)|)))) (and (let ((.cse4 (= ~waterLevel~0 1))) (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5) (and .cse3 .cse4 .cse6) .cse7)) (or .cse0 (and (<= |timeShift_getWaterLevel_#res#1| 2) (<= 2 |timeShift_getWaterLevel_#res#1|)) .cse1 .cse2 .cse8) (let ((.cse9 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse9 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse1 (and .cse9 .cse6) .cse2 .cse8)) (let ((.cse10 (<= ~waterLevel~0 2))) (or .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2 (and .cse3 .cse5 .cse10) (and .cse3 .cse10 .cse6) .cse7)))) [2021-12-17 15:09:50,421 INFO L854 garLoopResultBuilder]: At program point L541(line 541) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (and .cse1 .cse2 (= ~pumpRunning~0 0)) .cse3 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse3 .cse4 (and .cse5 .cse2 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse3 (and .cse1 .cse5 .cse2) .cse4))) [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L541-1(line 541) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L558(lines 558 568) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L858 garLoopResultBuilder]: For program point L554(lines 554 571) no Hoare annotation was computed. [2021-12-17 15:09:50,421 INFO L854 garLoopResultBuilder]: At program point L554-1(lines 546 574) the Hoare annotation is: (let ((.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not (= 0 |old(~pumpRunning~0)|))) (.cse7 (<= 1 ~switchedOnBeforeTS~0)) (.cse9 (= ~pumpRunning~0 0)) (.cse10 (not (<= 1 |old(~pumpRunning~0)|)))) (and (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse1 (and .cse0 .cse2) .cse3 .cse4)) (or .cse5 .cse1 .cse3 .cse4 (and (<= |timeShift_getWaterLevel_#res#1| 2) (<= 2 |timeShift_getWaterLevel_#res#1|) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~3#1| 2) (< 1 |timeShift___utac_acc__Specification5_spec__3_~tmp~3#1|))) (let ((.cse8 (<= ~waterLevel~0 2))) (or .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse3 (and .cse6 .cse7 .cse8 .cse9) (and .cse7 .cse2 .cse8) .cse10)) (let ((.cse11 (= ~waterLevel~0 1))) (or .cse5 .cse1 .cse3 (and .cse7 .cse11 .cse2) (and .cse6 .cse7 .cse11 .cse9) .cse10)))) [2021-12-17 15:09:50,422 INFO L858 garLoopResultBuilder]: For program point L63(lines 63 67) no Hoare annotation was computed. [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point L63-2(lines 59 70) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4))) [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point L699(lines 694 701) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 (and .cse2 (<= ~waterLevel~0 2) .cse3) .cse4))) [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point L658(line 658) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4))) [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 583 609) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (and .cse1 .cse2 (= ~pumpRunning~0 0)) .cse3 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse3 .cse4 (and .cse5 .cse2 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse3 (and .cse1 .cse5 .cse2) .cse4))) [2021-12-17 15:09:50,422 INFO L858 garLoopResultBuilder]: For program point L559(lines 559 565) no Hoare annotation was computed. [2021-12-17 15:09:50,422 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 583 609) no Hoare annotation was computed. [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point L650(line 650) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1 (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4))) [2021-12-17 15:09:50,422 INFO L858 garLoopResultBuilder]: For program point L650-1(line 650) no Hoare annotation was computed. [2021-12-17 15:09:50,422 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 155) no Hoare annotation was computed. [2021-12-17 15:09:50,422 INFO L854 garLoopResultBuilder]: At program point L832(lines 789 834) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= 1 ~pumpRunning~0)) (.cse1 (<= ~waterLevel~0 2)) (.cse2 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 0)) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse1 .cse2) (and .cse0 .cse3 (<= 2 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L799(lines 799 805) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L799-1(lines 799 805) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L861 garLoopResultBuilder]: At program point L952(lines 944 954) the Hoare annotation is: true [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L791(lines 791 795) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L965(lines 965 972) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L965-2(lines 965 972) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L854 garLoopResultBuilder]: At program point L862(lines 858 864) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L825(lines 825 829) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L854 garLoopResultBuilder]: At program point L825-2(lines 819 830) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= 1 ~pumpRunning~0)) (.cse1 (<= ~waterLevel~0 2)) (.cse2 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 0)) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse1 .cse2) (and .cse0 .cse3 (<= 2 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:50,423 INFO L861 garLoopResultBuilder]: At program point L974(lines 955 977) the Hoare annotation is: true [2021-12-17 15:09:50,423 INFO L854 garLoopResultBuilder]: At program point L941(lines 937 943) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L809(lines 809 815) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L858 garLoopResultBuilder]: For program point L809-1(lines 809 815) no Hoare annotation was computed. [2021-12-17 15:09:50,423 INFO L861 garLoopResultBuilder]: At program point L838(lines 779 842) the Hoare annotation is: true [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L801(line 801) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= 1 ~pumpRunning~0)) (.cse1 (<= ~waterLevel~0 2)) (.cse2 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 0)) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse1 .cse2) (and .cse0 .cse3 (<= 2 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L533(lines 528 535) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L835(lines 788 836) the Hoare annotation is: false [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point L790(lines 789 834) no Hoare annotation was computed. [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point L819(lines 819 830) no Hoare annotation was computed. [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L877(lines 872 880) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L811(line 811) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= 1 ~pumpRunning~0)) (.cse1 (<= ~waterLevel~0 2)) (.cse2 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 0)) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse1 .cse2) (and .cse0 .cse3 (<= 2 ~waterLevel~0) .cse1 .cse2))) [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L869(lines 865 871) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 71 82) no Hoare annotation was computed. [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point L75-1(lines 71 82) no Hoare annotation was computed. [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 71 82) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 ~pumpRunning~0))) (.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) .cse2) (or .cse0 (not (= ~pumpRunning~0 0)) .cse1 .cse3) (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 .cse2 .cse3))) [2021-12-17 15:09:50,424 INFO L854 garLoopResultBuilder]: At program point L632(line 632) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (and (= |processEnvironment__wrappee__methaneQuery_~tmp~4#1| 0) (= ~pumpRunning~0 0))))) [2021-12-17 15:09:50,424 INFO L858 garLoopResultBuilder]: For program point L626(lines 626 634) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L145(lines 136 149) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (= ~pumpRunning~0 0))) (or (and (<= 2 ~waterLevel~0) .cse2) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (and (= |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1| 1) .cse2))))) [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L622(lines 622 639) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L684(lines 684 690) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L682(line 682) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0)) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L684-2(lines 677 693) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (<= 2 ~waterLevel~0))) (or (and .cse2 (= ~pumpRunning~0 0)) (and (<= 1 ~pumpRunning~0) .cse2) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L682-1(line 682) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L773(lines 758 776) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (= ~pumpRunning~0 0))) (or (and (<= 2 ~waterLevel~0) .cse2) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (and (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~1#1| 0) .cse2))))) [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L674(lines 669 676) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L767(lines 767 771) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L767-2(lines 767 771) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point L637(line 637) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L637-1(lines 618 642) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 618 642) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or (not (<= 1 ~switchedOnBeforeTS~0)) .cse0 .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point L140(lines 140 146) no Hoare annotation was computed. [2021-12-17 15:09:50,425 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 618 642) no Hoare annotation was computed. [2021-12-17 15:09:50,426 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 713 721) no Hoare annotation was computed. [2021-12-17 15:09:50,430 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 713 721) the Hoare annotation is: true [2021-12-17 15:09:50,431 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 713 721) no Hoare annotation was computed. [2021-12-17 15:09:50,431 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 702 712) the Hoare annotation is: true [2021-12-17 15:09:50,431 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 702 712) no Hoare annotation was computed. [2021-12-17 15:09:50,431 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 702 712) no Hoare annotation was computed. [2021-12-17 15:09:50,431 INFO L861 garLoopResultBuilder]: At program point L100(lines 95 103) the Hoare annotation is: true [2021-12-17 15:09:50,433 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:09:50,434 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:09:50,500 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:09:50 BoogieIcfgContainer [2021-12-17 15:09:50,500 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:09:50,501 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:09:50,501 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:09:50,501 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:09:50,502 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:09:42" (3/4) ... [2021-12-17 15:09:50,504 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:09:50,508 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:09:50,508 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:09:50,508 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:09:50,508 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:09:50,508 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:09:50,509 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:09:50,509 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2021-12-17 15:09:50,509 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-17 15:09:50,514 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-17 15:09:50,526 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:09:50,543 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:09:50,544 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:09:50,544 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:09:50,544 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:50,545 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:09:50,576 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning)))) && ((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,576 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,577 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning))) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (((\result <= 2 && 2 <= \result) && tmp <= 2) && 1 < tmp))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || (((!(0 == \old(pumpRunning)) && 1 <= switchedOnBeforeTS) && waterLevel <= 2) && pumpRunning == 0)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning)))) && (((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || (((!(0 == \old(pumpRunning)) && 1 <= switchedOnBeforeTS) && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,577 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,577 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((((!(2 <= \old(waterLevel)) || (\result <= 2 && 2 <= \result)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:09:50,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || (\result == 1 && pumpRunning == 0)) [2021-12-17 15:09:50,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:09:50,579 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && ((((1 <= pumpRunning && 2 <= waterLevel) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:09:50,579 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((\result == 0 && tmp___0 == 0) && pumpRunning == 0)) [2021-12-17 15:09:50,628 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:09:50,628 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:09:50,629 INFO L158 Benchmark]: Toolchain (without parser) took 8735.49ms. Allocated memory was 86.0MB in the beginning and 176.2MB in the end (delta: 90.2MB). Free memory was 55.4MB in the beginning and 143.8MB in the end (delta: -88.4MB). Peak memory consumption was 135.4kB. Max. memory is 16.1GB. [2021-12-17 15:09:50,629 INFO L158 Benchmark]: CDTParser took 0.19ms. Allocated memory is still 86.0MB. Free memory was 43.0MB in the beginning and 43.0MB in the end (delta: 42.1kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:09:50,630 INFO L158 Benchmark]: CACSL2BoogieTranslator took 569.21ms. Allocated memory was 86.0MB in the beginning and 132.1MB in the end (delta: 46.1MB). Free memory was 55.2MB in the beginning and 100.6MB in the end (delta: -45.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,630 INFO L158 Benchmark]: Boogie Procedure Inliner took 50.20ms. Allocated memory is still 132.1MB. Free memory was 100.6MB in the beginning and 98.5MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,630 INFO L158 Benchmark]: Boogie Preprocessor took 40.30ms. Allocated memory is still 132.1MB. Free memory was 98.5MB in the beginning and 96.4MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,631 INFO L158 Benchmark]: RCFGBuilder took 432.06ms. Allocated memory is still 132.1MB. Free memory was 96.4MB in the beginning and 80.5MB in the end (delta: 15.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,631 INFO L158 Benchmark]: TraceAbstraction took 7509.89ms. Allocated memory was 132.1MB in the beginning and 176.2MB in the end (delta: 44.0MB). Free memory was 79.6MB in the beginning and 150.1MB in the end (delta: -70.4MB). Peak memory consumption was 80.5MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,631 INFO L158 Benchmark]: Witness Printer took 127.26ms. Allocated memory is still 176.2MB. Free memory was 150.1MB in the beginning and 143.8MB in the end (delta: 6.3MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2021-12-17 15:09:50,634 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.19ms. Allocated memory is still 86.0MB. Free memory was 43.0MB in the beginning and 43.0MB in the end (delta: 42.1kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 569.21ms. Allocated memory was 86.0MB in the beginning and 132.1MB in the end (delta: 46.1MB). Free memory was 55.2MB in the beginning and 100.6MB in the end (delta: -45.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 50.20ms. Allocated memory is still 132.1MB. Free memory was 100.6MB in the beginning and 98.5MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 40.30ms. Allocated memory is still 132.1MB. Free memory was 98.5MB in the beginning and 96.4MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 432.06ms. Allocated memory is still 132.1MB. Free memory was 96.4MB in the beginning and 80.5MB in the end (delta: 15.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7509.89ms. Allocated memory was 132.1MB in the beginning and 176.2MB in the end (delta: 44.0MB). Free memory was 79.6MB in the beginning and 150.1MB in the end (delta: -70.4MB). Peak memory consumption was 80.5MB. Max. memory is 16.1GB. * Witness Printer took 127.26ms. Allocated memory is still 176.2MB. Free memory was 150.1MB in the beginning and 143.8MB in the end (delta: 6.3MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 155]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 98 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.4s, OverallIterations: 10, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1702 SdHoareTripleChecker+Valid, 1.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1662 mSDsluCounter, 3957 SdHoareTripleChecker+Invalid, 1.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2731 mSDsCounter, 562 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2253 IncrementalHoareTripleChecker+Invalid, 2815 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 562 mSolverCounterUnsat, 1226 mSDtfsCounter, 2253 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 426 GetRequests, 320 SyntacticMatches, 2 SemanticMatches, 104 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 537 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=429occurred in iteration=9, InterpolantAutomatonStates: 99, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 10 MinimizatonAttempts, 123 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 981 PreInvPairs, 1170 NumberOfFragments, 1733 HoareAnnotationTreeSize, 981 FomulaSimplifications, 1548 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 45 FomulaSimplificationsInter, 9297 FormulaSimplificationTreeSizeReductionInter, 2.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.1s InterpolantComputationTime, 648 NumberOfCodeBlocks, 648 NumberOfCodeBlocksAsserted, 11 NumberOfCheckSat, 742 ConstructedInterpolants, 0 QuantifiedInterpolants, 1514 SizeOfPredicates, 3 NumberOfNonLiveVariables, 495 ConjunctsInSsa, 8 ConjunctsInUnsatCore, 12 InterpolantComputations, 9 PerfectInterpolantSequences, 103/138 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 865]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 872]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 136]: Loop Invariant Derived loop invariant: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || (\result == 1 && pumpRunning == 0)) - InvariantResult [Line: 789]: Loop Invariant Derived loop invariant: ((((splverifierCounter == 0 && waterLevel <= 2) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && 1 <= switchedOnBeforeTS) && 1 <= pumpRunning) && waterLevel <= 2) && systemActive == 1)) || ((((splverifierCounter == 0 && 1 <= pumpRunning) && 2 <= waterLevel) && waterLevel <= 2) && systemActive == 1) - InvariantResult [Line: 536]: Loop Invariant Derived loop invariant: ((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning)))) && ((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 644]: Loop Invariant Derived loop invariant: ((((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 95]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 546]: Loop Invariant Derived loop invariant: ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning))) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || (((\result <= 2 && 2 <= \result) && tmp <= 2) && 1 < tmp))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || (((!(0 == \old(pumpRunning)) && 1 <= switchedOnBeforeTS) && waterLevel <= 2) && pumpRunning == 0)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning)))) && (((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || (((!(0 == \old(pumpRunning)) && 1 <= switchedOnBeforeTS) && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 788]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 758]: Loop Invariant Derived loop invariant: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((\result == 0 && tmp___0 == 0) && pumpRunning == 0)) - InvariantResult [Line: 528]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 694]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 669]: Loop Invariant Derived loop invariant: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && ((((1 <= pumpRunning && 2 <= waterLevel) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: (((((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) && ((((!(2 <= \old(waterLevel)) || (\result <= 2 && 2 <= \result)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 858]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 955]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) && (((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 883]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 59]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) <= 2) || !(1 <= \old(switchedOnBeforeTS))) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(1 == systemActive)) || !(\old(pumpRunning) == 0))) && ((((!(2 <= \old(waterLevel)) || !(\old(waterLevel) <= 2)) || !(1 == systemActive)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 677]: Loop Invariant Derived loop invariant: (((!(1 <= switchedOnBeforeTS) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 == systemActive)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 779]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 944]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 893]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:09:50,704 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE