./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version ff03de63 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash c4da108453cefa034e9e2f20ae1a945f7f6bf5ea54205b9ec625406680c7ecea --- Real Ultimate output --- This is Ultimate 0.2.2-dev-ff03de6 [2021-12-21 13:14:09,251 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-21 13:14:09,253 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-21 13:14:09,301 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-21 13:14:09,302 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-21 13:14:09,304 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-21 13:14:09,306 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-21 13:14:09,308 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-21 13:14:09,310 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-21 13:14:09,314 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-21 13:14:09,315 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-21 13:14:09,316 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-21 13:14:09,316 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-21 13:14:09,318 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-21 13:14:09,320 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-21 13:14:09,322 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-21 13:14:09,323 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-21 13:14:09,324 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-21 13:14:09,326 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-21 13:14:09,331 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-21 13:14:09,332 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-21 13:14:09,333 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-21 13:14:09,334 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-21 13:14:09,335 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-21 13:14:09,341 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-21 13:14:09,341 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-21 13:14:09,341 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-21 13:14:09,343 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-21 13:14:09,343 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-21 13:14:09,344 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-21 13:14:09,344 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-21 13:14:09,345 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-21 13:14:09,346 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-21 13:14:09,347 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-21 13:14:09,348 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-21 13:14:09,349 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-21 13:14:09,349 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-21 13:14:09,349 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-21 13:14:09,350 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-21 13:14:09,350 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-21 13:14:09,351 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-21 13:14:09,352 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-21 13:14:09,382 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-21 13:14:09,382 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-21 13:14:09,383 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-21 13:14:09,383 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-21 13:14:09,384 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-21 13:14:09,384 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-21 13:14:09,385 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-21 13:14:09,385 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-21 13:14:09,385 INFO L138 SettingsManager]: * Use SBE=true [2021-12-21 13:14:09,385 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-21 13:14:09,386 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-21 13:14:09,386 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-21 13:14:09,387 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-21 13:14:09,387 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-21 13:14:09,387 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-21 13:14:09,387 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-21 13:14:09,387 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-21 13:14:09,388 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-21 13:14:09,388 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-21 13:14:09,388 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-21 13:14:09,388 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-21 13:14:09,388 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-21 13:14:09,389 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-21 13:14:09,389 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-21 13:14:09,389 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:14:09,389 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-21 13:14:09,389 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-21 13:14:09,390 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-21 13:14:09,390 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-21 13:14:09,390 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-21 13:14:09,390 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-21 13:14:09,390 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-21 13:14:09,391 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-21 13:14:09,391 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-21 13:14:09,391 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> c4da108453cefa034e9e2f20ae1a945f7f6bf5ea54205b9ec625406680c7ecea [2021-12-21 13:14:09,582 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-21 13:14:09,599 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-21 13:14:09,601 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-21 13:14:09,603 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-21 13:14:09,603 INFO L275 PluginConnector]: CDTParser initialized [2021-12-21 13:14:09,604 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c [2021-12-21 13:14:09,652 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/571395f95/52ec3c28638f4f2b8b2a12b2b74ffd87/FLAGbb715dc3e [2021-12-21 13:14:10,054 INFO L306 CDTParser]: Found 1 translation units. [2021-12-21 13:14:10,055 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c [2021-12-21 13:14:10,065 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/571395f95/52ec3c28638f4f2b8b2a12b2b74ffd87/FLAGbb715dc3e [2021-12-21 13:14:10,081 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/571395f95/52ec3c28638f4f2b8b2a12b2b74ffd87 [2021-12-21 13:14:10,084 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-21 13:14:10,085 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-21 13:14:10,095 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-21 13:14:10,096 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-21 13:14:10,099 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-21 13:14:10,100 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,100 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@6e4bdb8b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10, skipping insertion in model container [2021-12-21 13:14:10,101 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,106 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-21 13:14:10,149 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-21 13:14:10,307 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c[2044,2057] [2021-12-21 13:14:10,414 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:14:10,422 INFO L203 MainTranslator]: Completed pre-run [2021-12-21 13:14:10,434 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product47.cil.c[2044,2057] [2021-12-21 13:14:10,477 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:14:10,492 INFO L208 MainTranslator]: Completed translation [2021-12-21 13:14:10,492 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10 WrapperNode [2021-12-21 13:14:10,492 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-21 13:14:10,494 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-21 13:14:10,494 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-21 13:14:10,494 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-21 13:14:10,500 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,512 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,535 INFO L137 Inliner]: procedures = 55, calls = 157, calls flagged for inlining = 21, calls inlined = 18, statements flattened = 241 [2021-12-21 13:14:10,536 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-21 13:14:10,537 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-21 13:14:10,537 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-21 13:14:10,537 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-21 13:14:10,544 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,544 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,547 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,547 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,552 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,556 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,558 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,560 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-21 13:14:10,561 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-21 13:14:10,561 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-21 13:14:10,562 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-21 13:14:10,562 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,568 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:14:10,578 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:10,599 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-21 13:14:10,600 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-21 13:14:10,626 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-21 13:14:10,627 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-21 13:14:10,627 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-21 13:14:10,627 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-21 13:14:10,627 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-21 13:14:10,628 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-21 13:14:10,628 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-21 13:14:10,628 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-21 13:14:10,628 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-21 13:14:10,628 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-21 13:14:10,628 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-21 13:14:10,628 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:10,629 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:10,629 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-21 13:14:10,629 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-21 13:14:10,629 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-21 13:14:10,629 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-21 13:14:10,629 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-21 13:14:10,629 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-21 13:14:10,630 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-21 13:14:10,630 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-21 13:14:10,630 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-21 13:14:10,690 INFO L234 CfgBuilder]: Building ICFG [2021-12-21 13:14:10,691 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-21 13:14:11,031 INFO L275 CfgBuilder]: Performing block encoding [2021-12-21 13:14:11,039 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-21 13:14:11,039 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-21 13:14:11,041 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:11 BoogieIcfgContainer [2021-12-21 13:14:11,041 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-21 13:14:11,043 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-21 13:14:11,043 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-21 13:14:11,046 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-21 13:14:11,046 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.12 01:14:10" (1/3) ... [2021-12-21 13:14:11,047 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7c97debd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:14:11, skipping insertion in model container [2021-12-21 13:14:11,047 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (2/3) ... [2021-12-21 13:14:11,047 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7c97debd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:14:11, skipping insertion in model container [2021-12-21 13:14:11,048 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:11" (3/3) ... [2021-12-21 13:14:11,049 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product47.cil.c [2021-12-21 13:14:11,054 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-21 13:14:11,054 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-21 13:14:11,096 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-21 13:14:11,102 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-21 13:14:11,102 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-21 13:14:11,121 INFO L276 IsEmpty]: Start isEmpty. Operand has 100 states, 73 states have (on average 1.36986301369863) internal successors, (100), 82 states have internal predecessors, (100), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) [2021-12-21 13:14:11,128 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2021-12-21 13:14:11,128 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,129 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,129 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,134 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,135 INFO L85 PathProgramCache]: Analyzing trace with hash -707310338, now seen corresponding path program 1 times [2021-12-21 13:14:11,141 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,142 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [806031029] [2021-12-21 13:14:11,142 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,142 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,288 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,372 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-21 13:14:11,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,390 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,390 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,391 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [806031029] [2021-12-21 13:14:11,391 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [806031029] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,392 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,392 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-21 13:14:11,395 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1731480252] [2021-12-21 13:14:11,395 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,399 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-21 13:14:11,399 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,424 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-21 13:14:11,425 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:14:11,428 INFO L87 Difference]: Start difference. First operand has 100 states, 73 states have (on average 1.36986301369863) internal successors, (100), 82 states have internal predecessors, (100), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,464 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,464 INFO L93 Difference]: Finished difference Result 192 states and 259 transitions. [2021-12-21 13:14:11,465 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-21 13:14:11,466 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2021-12-21 13:14:11,466 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,473 INFO L225 Difference]: With dead ends: 192 [2021-12-21 13:14:11,473 INFO L226 Difference]: Without dead ends: 91 [2021-12-21 13:14:11,477 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:14:11,479 INFO L933 BasicCegarLoop]: 126 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 126 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,480 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 126 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,492 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 91 states. [2021-12-21 13:14:11,510 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 91 to 91. [2021-12-21 13:14:11,514 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 66 states have (on average 1.303030303030303) internal successors, (86), 74 states have internal predecessors, (86), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 12 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-21 13:14:11,522 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 117 transitions. [2021-12-21 13:14:11,526 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 117 transitions. Word has length 23 [2021-12-21 13:14:11,526 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,526 INFO L470 AbstractCegarLoop]: Abstraction has 91 states and 117 transitions. [2021-12-21 13:14:11,527 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,527 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 117 transitions. [2021-12-21 13:14:11,529 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-21 13:14:11,530 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,531 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,531 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-21 13:14:11,532 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,533 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,535 INFO L85 PathProgramCache]: Analyzing trace with hash 624156156, now seen corresponding path program 1 times [2021-12-21 13:14:11,535 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,535 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1083666941] [2021-12-21 13:14:11,536 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,536 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,612 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,653 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-21 13:14:11,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,662 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,662 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,663 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1083666941] [2021-12-21 13:14:11,663 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1083666941] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,663 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,664 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:14:11,665 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [135817820] [2021-12-21 13:14:11,665 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,667 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:14:11,667 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,668 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:14:11,669 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,669 INFO L87 Difference]: Start difference. First operand 91 states and 117 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,703 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,706 INFO L93 Difference]: Finished difference Result 144 states and 184 transitions. [2021-12-21 13:14:11,706 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:14:11,707 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2021-12-21 13:14:11,707 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,709 INFO L225 Difference]: With dead ends: 144 [2021-12-21 13:14:11,711 INFO L226 Difference]: Without dead ends: 82 [2021-12-21 13:14:11,712 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,714 INFO L933 BasicCegarLoop]: 104 mSDtfsCounter, 16 mSDsluCounter, 83 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 187 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,715 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 187 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,717 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 82 states. [2021-12-21 13:14:11,726 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 82 to 82. [2021-12-21 13:14:11,729 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 82 states, 60 states have (on average 1.3166666666666667) internal successors, (79), 68 states have internal predecessors, (79), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-21 13:14:11,731 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 82 states to 82 states and 105 transitions. [2021-12-21 13:14:11,733 INFO L78 Accepts]: Start accepts. Automaton has 82 states and 105 transitions. Word has length 24 [2021-12-21 13:14:11,733 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,733 INFO L470 AbstractCegarLoop]: Abstraction has 82 states and 105 transitions. [2021-12-21 13:14:11,734 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,734 INFO L276 IsEmpty]: Start isEmpty. Operand 82 states and 105 transitions. [2021-12-21 13:14:11,735 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2021-12-21 13:14:11,736 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,736 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,736 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-21 13:14:11,736 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,737 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,737 INFO L85 PathProgramCache]: Analyzing trace with hash -1800989914, now seen corresponding path program 1 times [2021-12-21 13:14:11,737 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,737 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1035859912] [2021-12-21 13:14:11,737 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,737 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,767 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,815 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:14:11,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,823 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,823 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,824 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1035859912] [2021-12-21 13:14:11,824 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1035859912] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,825 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,825 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:14:11,825 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2108762072] [2021-12-21 13:14:11,825 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,826 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:14:11,826 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,827 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:14:11,828 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,828 INFO L87 Difference]: Start difference. First operand 82 states and 105 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,863 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,863 INFO L93 Difference]: Finished difference Result 231 states and 301 transitions. [2021-12-21 13:14:11,864 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:14:11,864 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 28 [2021-12-21 13:14:11,865 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,866 INFO L225 Difference]: With dead ends: 231 [2021-12-21 13:14:11,866 INFO L226 Difference]: Without dead ends: 156 [2021-12-21 13:14:11,867 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,868 INFO L933 BasicCegarLoop]: 133 mSDtfsCounter, 85 mSDsluCounter, 95 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 85 SdHoareTripleChecker+Valid, 228 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,869 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [85 Valid, 228 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,870 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 156 states. [2021-12-21 13:14:11,888 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 156 to 153. [2021-12-21 13:14:11,889 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 153 states, 110 states have (on average 1.3363636363636364) internal successors, (147), 125 states have internal predecessors, (147), 26 states have call successors, (26), 16 states have call predecessors, (26), 16 states have return successors, (26), 19 states have call predecessors, (26), 26 states have call successors, (26) [2021-12-21 13:14:11,890 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 153 states to 153 states and 199 transitions. [2021-12-21 13:14:11,890 INFO L78 Accepts]: Start accepts. Automaton has 153 states and 199 transitions. Word has length 28 [2021-12-21 13:14:11,890 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,891 INFO L470 AbstractCegarLoop]: Abstraction has 153 states and 199 transitions. [2021-12-21 13:14:11,891 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,891 INFO L276 IsEmpty]: Start isEmpty. Operand 153 states and 199 transitions. [2021-12-21 13:14:11,892 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-21 13:14:11,893 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,893 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,893 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-21 13:14:11,893 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,894 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,894 INFO L85 PathProgramCache]: Analyzing trace with hash -40246052, now seen corresponding path program 1 times [2021-12-21 13:14:11,894 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,894 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [265813290] [2021-12-21 13:14:11,895 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,895 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,911 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,967 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:11,969 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,978 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,979 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,979 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [265813290] [2021-12-21 13:14:11,979 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [265813290] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,980 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,980 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:11,980 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2056769160] [2021-12-21 13:14:11,980 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,981 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:11,981 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,981 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:11,982 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:11,982 INFO L87 Difference]: Start difference. First operand 153 states and 199 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:12,100 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:12,100 INFO L93 Difference]: Finished difference Result 445 states and 588 transitions. [2021-12-21 13:14:12,101 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:12,101 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2021-12-21 13:14:12,101 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:12,111 INFO L225 Difference]: With dead ends: 445 [2021-12-21 13:14:12,111 INFO L226 Difference]: Without dead ends: 299 [2021-12-21 13:14:12,116 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-21 13:14:12,122 INFO L933 BasicCegarLoop]: 115 mSDtfsCounter, 76 mSDsluCounter, 403 mSDsCounter, 0 mSdLazyCounter, 52 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 79 SdHoareTripleChecker+Valid, 518 SdHoareTripleChecker+Invalid, 56 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 52 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:12,124 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [79 Valid, 518 Invalid, 56 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 52 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:12,126 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 299 states. [2021-12-21 13:14:12,163 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 299 to 293. [2021-12-21 13:14:12,167 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 293 states, 208 states have (on average 1.3269230769230769) internal successors, (276), 237 states have internal predecessors, (276), 52 states have call successors, (52), 32 states have call predecessors, (52), 32 states have return successors, (54), 38 states have call predecessors, (54), 52 states have call successors, (54) [2021-12-21 13:14:12,171 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 293 states to 293 states and 382 transitions. [2021-12-21 13:14:12,172 INFO L78 Accepts]: Start accepts. Automaton has 293 states and 382 transitions. Word has length 32 [2021-12-21 13:14:12,172 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:12,173 INFO L470 AbstractCegarLoop]: Abstraction has 293 states and 382 transitions. [2021-12-21 13:14:12,173 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:12,173 INFO L276 IsEmpty]: Start isEmpty. Operand 293 states and 382 transitions. [2021-12-21 13:14:12,181 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2021-12-21 13:14:12,182 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:12,182 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:12,182 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-21 13:14:12,183 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:12,183 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:12,183 INFO L85 PathProgramCache]: Analyzing trace with hash 1430200224, now seen corresponding path program 1 times [2021-12-21 13:14:12,184 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:12,184 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2120767607] [2021-12-21 13:14:12,184 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:12,185 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:12,212 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,292 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:12,296 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,299 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-21 13:14:12,303 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,309 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:12,309 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:12,309 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2120767607] [2021-12-21 13:14:12,310 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2120767607] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:12,310 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:12,310 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:12,310 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1031103431] [2021-12-21 13:14:12,310 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:12,311 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:12,311 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:12,311 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:12,312 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:12,312 INFO L87 Difference]: Start difference. First operand 293 states and 382 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:14:12,586 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:12,586 INFO L93 Difference]: Finished difference Result 775 states and 1023 transitions. [2021-12-21 13:14:12,587 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:12,587 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 36 [2021-12-21 13:14:12,588 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:12,592 INFO L225 Difference]: With dead ends: 775 [2021-12-21 13:14:12,592 INFO L226 Difference]: Without dead ends: 489 [2021-12-21 13:14:12,594 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-21 13:14:12,597 INFO L933 BasicCegarLoop]: 95 mSDtfsCounter, 128 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 217 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 135 SdHoareTripleChecker+Valid, 246 SdHoareTripleChecker+Invalid, 266 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 217 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:12,597 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [135 Valid, 246 Invalid, 266 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 217 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:12,599 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 489 states. [2021-12-21 13:14:12,646 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 489 to 475. [2021-12-21 13:14:12,647 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 475 states, 342 states have (on average 1.2748538011695907) internal successors, (436), 375 states have internal predecessors, (436), 72 states have call successors, (72), 60 states have call predecessors, (72), 60 states have return successors, (92), 66 states have call predecessors, (92), 72 states have call successors, (92) [2021-12-21 13:14:12,650 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 475 states to 475 states and 600 transitions. [2021-12-21 13:14:12,651 INFO L78 Accepts]: Start accepts. Automaton has 475 states and 600 transitions. Word has length 36 [2021-12-21 13:14:12,651 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:12,651 INFO L470 AbstractCegarLoop]: Abstraction has 475 states and 600 transitions. [2021-12-21 13:14:12,651 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:14:12,652 INFO L276 IsEmpty]: Start isEmpty. Operand 475 states and 600 transitions. [2021-12-21 13:14:12,654 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 59 [2021-12-21 13:14:12,654 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:12,655 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:12,655 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-21 13:14:12,656 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:12,656 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:12,656 INFO L85 PathProgramCache]: Analyzing trace with hash -1476072605, now seen corresponding path program 1 times [2021-12-21 13:14:12,656 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:12,656 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [928062255] [2021-12-21 13:14:12,657 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:12,657 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:12,673 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,697 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:12,699 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,705 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:12,710 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,729 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:12,731 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,734 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:12,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,738 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 49 [2021-12-21 13:14:12,739 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,742 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:12,742 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:12,742 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [928062255] [2021-12-21 13:14:12,743 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [928062255] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:12,743 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:12,747 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-21 13:14:12,747 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [774876718] [2021-12-21 13:14:12,748 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:12,748 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-21 13:14:12,748 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:12,749 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-21 13:14:12,749 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-21 13:14:12,750 INFO L87 Difference]: Start difference. First operand 475 states and 600 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-21 13:14:13,250 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:13,251 INFO L93 Difference]: Finished difference Result 1097 states and 1418 transitions. [2021-12-21 13:14:13,252 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-21 13:14:13,252 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) Word has length 58 [2021-12-21 13:14:13,253 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:13,257 INFO L225 Difference]: With dead ends: 1097 [2021-12-21 13:14:13,258 INFO L226 Difference]: Without dead ends: 629 [2021-12-21 13:14:13,261 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 41 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=86, Invalid=186, Unknown=0, NotChecked=0, Total=272 [2021-12-21 13:14:13,262 INFO L933 BasicCegarLoop]: 113 mSDtfsCounter, 366 mSDsluCounter, 176 mSDsCounter, 0 mSdLazyCounter, 359 mSolverCounterSat, 154 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 370 SdHoareTripleChecker+Valid, 289 SdHoareTripleChecker+Invalid, 513 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 154 IncrementalHoareTripleChecker+Valid, 359 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:13,264 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [370 Valid, 289 Invalid, 513 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [154 Valid, 359 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-21 13:14:13,266 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 629 states. [2021-12-21 13:14:13,307 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 629 to 563. [2021-12-21 13:14:13,308 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 563 states, 410 states have (on average 1.2439024390243902) internal successors, (510), 443 states have internal predecessors, (510), 80 states have call successors, (80), 60 states have call predecessors, (80), 72 states have return successors, (112), 82 states have call predecessors, (112), 80 states have call successors, (112) [2021-12-21 13:14:13,311 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 563 states to 563 states and 702 transitions. [2021-12-21 13:14:13,312 INFO L78 Accepts]: Start accepts. Automaton has 563 states and 702 transitions. Word has length 58 [2021-12-21 13:14:13,312 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:13,312 INFO L470 AbstractCegarLoop]: Abstraction has 563 states and 702 transitions. [2021-12-21 13:14:13,312 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-21 13:14:13,313 INFO L276 IsEmpty]: Start isEmpty. Operand 563 states and 702 transitions. [2021-12-21 13:14:13,314 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 59 [2021-12-21 13:14:13,314 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:13,314 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:13,314 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-21 13:14:13,315 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:13,315 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:13,315 INFO L85 PathProgramCache]: Analyzing trace with hash -1498704859, now seen corresponding path program 1 times [2021-12-21 13:14:13,315 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:13,316 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [442376995] [2021-12-21 13:14:13,316 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:13,316 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:13,329 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,346 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:13,347 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,352 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:13,356 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,376 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:13,378 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,381 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:13,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,385 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 49 [2021-12-21 13:14:13,386 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,404 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:13,404 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:13,404 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [442376995] [2021-12-21 13:14:13,404 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [442376995] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:13,405 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:13,405 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-21 13:14:13,405 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [115927435] [2021-12-21 13:14:13,405 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:13,405 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-21 13:14:13,406 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:13,406 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-21 13:14:13,406 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-21 13:14:13,407 INFO L87 Difference]: Start difference. First operand 563 states and 702 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:13,638 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:13,638 INFO L93 Difference]: Finished difference Result 1153 states and 1478 transitions. [2021-12-21 13:14:13,639 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-21 13:14:13,639 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 58 [2021-12-21 13:14:13,640 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:13,643 INFO L225 Difference]: With dead ends: 1153 [2021-12-21 13:14:13,643 INFO L226 Difference]: Without dead ends: 597 [2021-12-21 13:14:13,645 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-21 13:14:13,648 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 129 mSDsluCounter, 169 mSDsCounter, 0 mSdLazyCounter, 264 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 130 SdHoareTripleChecker+Valid, 255 SdHoareTripleChecker+Invalid, 322 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 264 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:13,649 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [130 Valid, 255 Invalid, 322 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 264 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:13,650 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 597 states. [2021-12-21 13:14:13,680 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 597 to 575. [2021-12-21 13:14:13,681 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 575 states, 422 states have (on average 1.2369668246445498) internal successors, (522), 455 states have internal predecessors, (522), 80 states have call successors, (80), 60 states have call predecessors, (80), 72 states have return successors, (112), 82 states have call predecessors, (112), 80 states have call successors, (112) [2021-12-21 13:14:13,685 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 575 states to 575 states and 714 transitions. [2021-12-21 13:14:13,686 INFO L78 Accepts]: Start accepts. Automaton has 575 states and 714 transitions. Word has length 58 [2021-12-21 13:14:13,686 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:13,686 INFO L470 AbstractCegarLoop]: Abstraction has 575 states and 714 transitions. [2021-12-21 13:14:13,688 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:13,688 INFO L276 IsEmpty]: Start isEmpty. Operand 575 states and 714 transitions. [2021-12-21 13:14:13,690 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 59 [2021-12-21 13:14:13,691 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:13,691 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:13,691 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-21 13:14:13,692 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:13,693 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:13,693 INFO L85 PathProgramCache]: Analyzing trace with hash -1201312991, now seen corresponding path program 1 times [2021-12-21 13:14:13,693 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:13,693 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1873131198] [2021-12-21 13:14:13,693 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:13,694 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:13,717 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,762 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:13,764 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:13,776 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,790 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:13,793 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,796 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:13,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,800 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 49 [2021-12-21 13:14:13,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,804 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:13,804 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:13,804 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1873131198] [2021-12-21 13:14:13,805 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1873131198] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:13,805 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:13,805 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:13,805 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [549626584] [2021-12-21 13:14:13,805 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:13,806 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:13,806 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:13,806 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:13,806 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:13,807 INFO L87 Difference]: Start difference. First operand 575 states and 714 transitions. Second operand has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-21 13:14:14,159 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:14,159 INFO L93 Difference]: Finished difference Result 1629 states and 2110 transitions. [2021-12-21 13:14:14,159 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-21 13:14:14,160 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) Word has length 58 [2021-12-21 13:14:14,160 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:14,166 INFO L225 Difference]: With dead ends: 1629 [2021-12-21 13:14:14,166 INFO L226 Difference]: Without dead ends: 1061 [2021-12-21 13:14:14,169 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 14 SyntacticMatches, 1 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-21 13:14:14,170 INFO L933 BasicCegarLoop]: 134 mSDtfsCounter, 334 mSDsluCounter, 139 mSDsCounter, 0 mSdLazyCounter, 254 mSolverCounterSat, 142 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 337 SdHoareTripleChecker+Valid, 273 SdHoareTripleChecker+Invalid, 396 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 142 IncrementalHoareTripleChecker+Valid, 254 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:14,170 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [337 Valid, 273 Invalid, 396 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [142 Valid, 254 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:14,172 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1061 states. [2021-12-21 13:14:14,216 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1061 to 1049. [2021-12-21 13:14:14,218 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1049 states, 776 states have (on average 1.2164948453608246) internal successors, (944), 827 states have internal predecessors, (944), 142 states have call successors, (142), 126 states have call predecessors, (142), 130 states have return successors, (228), 140 states have call predecessors, (228), 142 states have call successors, (228) [2021-12-21 13:14:14,224 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1049 states to 1049 states and 1314 transitions. [2021-12-21 13:14:14,224 INFO L78 Accepts]: Start accepts. Automaton has 1049 states and 1314 transitions. Word has length 58 [2021-12-21 13:14:14,226 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:14,226 INFO L470 AbstractCegarLoop]: Abstraction has 1049 states and 1314 transitions. [2021-12-21 13:14:14,226 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-21 13:14:14,226 INFO L276 IsEmpty]: Start isEmpty. Operand 1049 states and 1314 transitions. [2021-12-21 13:14:14,228 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2021-12-21 13:14:14,228 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:14,228 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:14,229 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-21 13:14:14,229 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:14,229 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:14,229 INFO L85 PathProgramCache]: Analyzing trace with hash -238505913, now seen corresponding path program 1 times [2021-12-21 13:14:14,230 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:14,230 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [858906884] [2021-12-21 13:14:14,230 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:14,230 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:14,249 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,286 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:14,288 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,298 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-21 13:14:14,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,319 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-21 13:14:14,325 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,355 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:14,358 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,391 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:14,392 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,408 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 53 [2021-12-21 13:14:14,409 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,411 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-21 13:14:14,412 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:14,412 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [858906884] [2021-12-21 13:14:14,412 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [858906884] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-21 13:14:14,412 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [865649506] [2021-12-21 13:14:14,412 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:14,413 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:14,413 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:14,419 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-21 13:14:14,442 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-21 13:14:14,509 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,511 INFO L263 TraceCheckSpWp]: Trace formula consists of 382 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-21 13:14:14,517 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-21 13:14:14,846 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:14,847 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-21 13:14:14,847 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [865649506] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:14,847 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-21 13:14:14,847 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 21 [2021-12-21 13:14:14,847 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1889549094] [2021-12-21 13:14:14,847 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:14,848 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:14,848 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:14,848 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:14,849 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=52, Invalid=368, Unknown=0, NotChecked=0, Total=420 [2021-12-21 13:14:14,849 INFO L87 Difference]: Start difference. First operand 1049 states and 1314 transitions. Second operand has 8 states, 8 states have (on average 6.125) internal successors, (49), 6 states have internal predecessors, (49), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-21 13:14:15,009 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:15,010 INFO L93 Difference]: Finished difference Result 2049 states and 2579 transitions. [2021-12-21 13:14:15,010 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:15,011 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.125) internal successors, (49), 6 states have internal predecessors, (49), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) Word has length 62 [2021-12-21 13:14:15,011 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:15,017 INFO L225 Difference]: With dead ends: 2049 [2021-12-21 13:14:15,017 INFO L226 Difference]: Without dead ends: 1007 [2021-12-21 13:14:15,020 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 82 GetRequests, 63 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=52, Invalid=368, Unknown=0, NotChecked=0, Total=420 [2021-12-21 13:14:15,023 INFO L933 BasicCegarLoop]: 191 mSDtfsCounter, 71 mSDsluCounter, 510 mSDsCounter, 0 mSdLazyCounter, 172 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 75 SdHoareTripleChecker+Valid, 701 SdHoareTripleChecker+Invalid, 175 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 172 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:15,024 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [75 Valid, 701 Invalid, 175 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 172 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:15,025 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1007 states. [2021-12-21 13:14:15,071 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1007 to 1003. [2021-12-21 13:14:15,073 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1003 states, 740 states have (on average 1.2027027027027026) internal successors, (890), 789 states have internal predecessors, (890), 138 states have call successors, (138), 122 states have call predecessors, (138), 124 states have return successors, (200), 134 states have call predecessors, (200), 138 states have call successors, (200) [2021-12-21 13:14:15,077 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1003 states to 1003 states and 1228 transitions. [2021-12-21 13:14:15,078 INFO L78 Accepts]: Start accepts. Automaton has 1003 states and 1228 transitions. Word has length 62 [2021-12-21 13:14:15,078 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:15,078 INFO L470 AbstractCegarLoop]: Abstraction has 1003 states and 1228 transitions. [2021-12-21 13:14:15,079 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.125) internal successors, (49), 6 states have internal predecessors, (49), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-21 13:14:15,079 INFO L276 IsEmpty]: Start isEmpty. Operand 1003 states and 1228 transitions. [2021-12-21 13:14:15,082 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2021-12-21 13:14:15,082 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:15,083 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:15,112 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-21 13:14:15,299 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:15,299 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:15,300 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:15,300 INFO L85 PathProgramCache]: Analyzing trace with hash -353852961, now seen corresponding path program 1 times [2021-12-21 13:14:15,300 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:15,300 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [664781811] [2021-12-21 13:14:15,300 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:15,300 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:15,315 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:15,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,370 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:15,376 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,402 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-21 13:14:15,406 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,410 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:15,412 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,414 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:15,415 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,417 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-21 13:14:15,418 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2021-12-21 13:14:15,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,428 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2021-12-21 13:14:15,430 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,438 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-21 13:14:15,439 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:15,439 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [664781811] [2021-12-21 13:14:15,439 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [664781811] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:15,439 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:15,440 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-21 13:14:15,440 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1986057744] [2021-12-21 13:14:15,440 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:15,441 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:15,441 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:15,442 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:15,442 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-21 13:14:15,442 INFO L87 Difference]: Start difference. First operand 1003 states and 1228 transitions. Second operand has 8 states, 8 states have (on average 8.5) internal successors, (68), 4 states have internal predecessors, (68), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-21 13:14:15,794 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:15,795 INFO L93 Difference]: Finished difference Result 1335 states and 1642 transitions. [2021-12-21 13:14:15,795 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-21 13:14:15,795 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 8.5) internal successors, (68), 4 states have internal predecessors, (68), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) Word has length 89 [2021-12-21 13:14:15,796 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:15,799 INFO L225 Difference]: With dead ends: 1335 [2021-12-21 13:14:15,799 INFO L226 Difference]: Without dead ends: 592 [2021-12-21 13:14:15,801 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 20 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=68, Invalid=172, Unknown=0, NotChecked=0, Total=240 [2021-12-21 13:14:15,801 INFO L933 BasicCegarLoop]: 123 mSDtfsCounter, 294 mSDsluCounter, 187 mSDsCounter, 0 mSdLazyCounter, 323 mSolverCounterSat, 127 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 304 SdHoareTripleChecker+Valid, 310 SdHoareTripleChecker+Invalid, 450 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 127 IncrementalHoareTripleChecker+Valid, 323 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:15,802 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [304 Valid, 310 Invalid, 450 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [127 Valid, 323 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:15,803 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 592 states. [2021-12-21 13:14:15,828 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 592 to 572. [2021-12-21 13:14:15,829 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 572 states, 420 states have (on average 1.1571428571428573) internal successors, (486), 450 states have internal predecessors, (486), 81 states have call successors, (81), 60 states have call predecessors, (81), 70 states have return successors, (128), 81 states have call predecessors, (128), 81 states have call successors, (128) [2021-12-21 13:14:15,832 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 572 states to 572 states and 695 transitions. [2021-12-21 13:14:15,832 INFO L78 Accepts]: Start accepts. Automaton has 572 states and 695 transitions. Word has length 89 [2021-12-21 13:14:15,833 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:15,833 INFO L470 AbstractCegarLoop]: Abstraction has 572 states and 695 transitions. [2021-12-21 13:14:15,833 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 8.5) internal successors, (68), 4 states have internal predecessors, (68), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-21 13:14:15,833 INFO L276 IsEmpty]: Start isEmpty. Operand 572 states and 695 transitions. [2021-12-21 13:14:15,835 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 107 [2021-12-21 13:14:15,835 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:15,836 INFO L514 BasicCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:15,836 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-21 13:14:15,836 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:15,836 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:15,837 INFO L85 PathProgramCache]: Analyzing trace with hash -753408287, now seen corresponding path program 1 times [2021-12-21 13:14:15,837 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:15,837 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1708440714] [2021-12-21 13:14:15,837 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:15,837 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:15,850 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,884 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:15,885 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,894 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:14:15,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,904 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-21 13:14:15,906 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,909 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:15,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,913 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:15,913 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,915 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-21 13:14:15,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,922 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2021-12-21 13:14:15,923 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2021-12-21 13:14:15,938 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:15,983 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:15,985 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:16,001 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2021-12-21 13:14:16,002 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:16,004 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-21 13:14:16,004 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:16,007 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 97 [2021-12-21 13:14:16,008 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:16,032 INFO L134 CoverageAnalysis]: Checked inductivity of 44 backedges. 14 proven. 12 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2021-12-21 13:14:16,032 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:16,032 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1708440714] [2021-12-21 13:14:16,033 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1708440714] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-21 13:14:16,033 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [338226998] [2021-12-21 13:14:16,033 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:16,033 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:16,033 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:16,034 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-21 13:14:16,062 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-21 13:14:16,128 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:16,131 INFO L263 TraceCheckSpWp]: Trace formula consists of 481 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-21 13:14:16,134 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-21 13:14:16,396 INFO L134 CoverageAnalysis]: Checked inductivity of 44 backedges. 35 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-21 13:14:16,396 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-21 13:14:16,396 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [338226998] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:16,396 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-21 13:14:16,397 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [14] total 19 [2021-12-21 13:14:16,397 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [79024382] [2021-12-21 13:14:16,397 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:16,397 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:16,398 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:16,398 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:16,398 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=294, Unknown=0, NotChecked=0, Total=342 [2021-12-21 13:14:16,399 INFO L87 Difference]: Start difference. First operand 572 states and 695 transitions. Second operand has 8 states, 8 states have (on average 9.375) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-21 13:14:16,513 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:16,514 INFO L93 Difference]: Finished difference Result 1000 states and 1235 transitions. [2021-12-21 13:14:16,514 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:16,515 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.375) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) Word has length 106 [2021-12-21 13:14:16,515 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:16,516 INFO L225 Difference]: With dead ends: 1000 [2021-12-21 13:14:16,516 INFO L226 Difference]: Without dead ends: 0 [2021-12-21 13:14:16,518 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 140 GetRequests, 121 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 43 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=60, Invalid=360, Unknown=0, NotChecked=0, Total=420 [2021-12-21 13:14:16,519 INFO L933 BasicCegarLoop]: 174 mSDtfsCounter, 68 mSDsluCounter, 864 mSDsCounter, 0 mSdLazyCounter, 120 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 1038 SdHoareTripleChecker+Invalid, 126 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 120 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:16,519 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 1038 Invalid, 126 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 120 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:16,520 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-21 13:14:16,520 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-21 13:14:16,520 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-21 13:14:16,520 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-21 13:14:16,521 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 106 [2021-12-21 13:14:16,521 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:16,521 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-21 13:14:16,521 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.375) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-21 13:14:16,521 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-21 13:14:16,522 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-21 13:14:16,524 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-21 13:14:16,555 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-21 13:14:16,738 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-21 13:14:16,740 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-21 13:14:20,114 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 342 349) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (not (<= 2 ~waterLevel~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse5 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse4 .cse5) (or .cse0 .cse1 .cse4) (or .cse0 .cse3 .cse2 .cse5))) [2021-12-21 13:14:20,115 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 342 349) no Hoare annotation was computed. [2021-12-21 13:14:20,115 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 342 349) no Hoare annotation was computed. [2021-12-21 13:14:20,115 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 258 264) no Hoare annotation was computed. [2021-12-21 13:14:20,115 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 258 264) the Hoare annotation is: true [2021-12-21 13:14:20,115 INFO L858 garLoopResultBuilder]: For program point L162-1(lines 158 169) no Hoare annotation was computed. [2021-12-21 13:14:20,115 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 158 169) the Hoare annotation is: (let ((.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse5 (not (<= 1 |old(~methaneLevelCritical~0)|)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse2 .cse4) (or .cse3 .cse2 .cse5 .cse4) (or .cse3 .cse1 .cse2 .cse5))) [2021-12-21 13:14:20,116 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 158 169) no Hoare annotation was computed. [2021-12-21 13:14:20,116 INFO L858 garLoopResultBuilder]: For program point L897(line 897) no Hoare annotation was computed. [2021-12-21 13:14:20,116 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 876 905) no Hoare annotation was computed. [2021-12-21 13:14:20,116 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 876 905) the Hoare annotation is: true [2021-12-21 13:14:20,116 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 894) no Hoare annotation was computed. [2021-12-21 13:14:20,116 INFO L861 garLoopResultBuilder]: At program point L890-1(lines 890 894) the Hoare annotation is: true [2021-12-21 13:14:20,116 INFO L858 garLoopResultBuilder]: For program point L887(line 887) no Hoare annotation was computed. [2021-12-21 13:14:20,117 INFO L861 garLoopResultBuilder]: At program point L886-2(lines 886 900) the Hoare annotation is: true [2021-12-21 13:14:20,117 INFO L861 garLoopResultBuilder]: At program point L882(line 882) the Hoare annotation is: true [2021-12-21 13:14:20,117 INFO L858 garLoopResultBuilder]: For program point L882-1(line 882) no Hoare annotation was computed. [2021-12-21 13:14:20,117 INFO L861 garLoopResultBuilder]: At program point L901(lines 876 905) the Hoare annotation is: true [2021-12-21 13:14:20,117 INFO L854 garLoopResultBuilder]: At program point L366(lines 361 369) the Hoare annotation is: (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= 0 ~systemActive~0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse7 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse2 (and .cse4 .cse5 .cse3) .cse6) (or .cse1 (and .cse4 .cse5) .cse2) (or .cse0 .cse7 .cse6) (or .cse1 .cse7))) [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point L238-1(lines 237 256) no Hoare annotation was computed. [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point L300(lines 300 308) no Hoare annotation was computed. [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point L296(lines 296 313) no Hoare annotation was computed. [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 234 257) no Hoare annotation was computed. [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point L65(lines 65 71) no Hoare annotation was computed. [2021-12-21 13:14:20,118 INFO L858 garLoopResultBuilder]: For program point L61(lines 61 74) no Hoare annotation was computed. [2021-12-21 13:14:20,119 INFO L854 garLoopResultBuilder]: At program point L61-1(lines 53 77) the Hoare annotation is: (let ((.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse6 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= 0 ~systemActive~0)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse0 .cse5 .cse3 .cse2) (or .cse1 .cse5 .cse3) (or .cse5 (and .cse6 (<= 2 ~waterLevel~0)) (and .cse1 .cse6) .cse7 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse6)) (or .cse0 .cse5 .cse7 .cse2) (or (and .cse1 .cse6 .cse2) .cse0 .cse7 .cse4))) [2021-12-21 13:14:20,119 INFO L858 garLoopResultBuilder]: For program point L83(line 83) no Hoare annotation was computed. [2021-12-21 13:14:20,119 INFO L854 garLoopResultBuilder]: At program point L306(line 306) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse0 .cse2) (or .cse3 .cse1 .cse4) (or .cse3 .cse2 .cse4) (or .cse3 .cse0 .cse1))) [2021-12-21 13:14:20,119 INFO L854 garLoopResultBuilder]: At program point L302(line 302) the Hoare annotation is: (let ((.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse2 .cse4) (or .cse3 .cse5 .cse4) (or .cse3 .cse1 .cse5) (or .cse3 .cse1 .cse2) (or .cse1 .cse5 (and .cse0 (<= 1 |timeShift_processEnvironment_~tmp~2#1|))))) [2021-12-21 13:14:20,119 INFO L854 garLoopResultBuilder]: At program point L298(line 298) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (= 0 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse4 .cse2 .cse5) (or .cse4 .cse3 .cse5) (or .cse4 .cse1 .cse3) (or .cse4 .cse1 .cse2))) [2021-12-21 13:14:20,119 INFO L858 garLoopResultBuilder]: For program point L298-1(line 298) no Hoare annotation was computed. [2021-12-21 13:14:20,120 INFO L854 garLoopResultBuilder]: At program point L59(line 59) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and .cse7 .cse6)) (.cse3 (not (= 0 ~systemActive~0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse0 .cse5 .cse2 .cse6) (or .cse7 .cse5 .cse2) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse7 .cse5 (<= 2 ~waterLevel~0) .cse4) (or .cse0 .cse5 .cse4 .cse6)))) [2021-12-21 13:14:20,120 INFO L858 garLoopResultBuilder]: For program point L59-1(line 59) no Hoare annotation was computed. [2021-12-21 13:14:20,120 INFO L854 garLoopResultBuilder]: At program point L311(line 311) the Hoare annotation is: (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse1 .cse4) (or .cse3 .cse5 .cse4) (or .cse0 .cse5 .cse2))) [2021-12-21 13:14:20,120 INFO L854 garLoopResultBuilder]: At program point L311-1(lines 292 316) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (not (= 0 ~systemActive~0))) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 .cse2) (or .cse0 .cse5 .cse6) (or .cse0 .cse2 .cse6) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4 .cse1 (<= 2 ~waterLevel~0) .cse5) (or .cse0 .cse1 .cse5 .cse3))) [2021-12-21 13:14:20,120 INFO L858 garLoopResultBuilder]: For program point L245-1(lines 245 251) no Hoare annotation was computed. [2021-12-21 13:14:20,121 INFO L854 garLoopResultBuilder]: At program point L84(lines 79 86) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1) (or .cse2 .cse3 .cse4) (or .cse2 .cse1 .cse4) (or .cse0 .cse3))) [2021-12-21 13:14:20,121 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 234 257) the Hoare annotation is: (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and (= ~pumpRunning~0 0) .cse7)) (.cse3 (not (= 0 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse7))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse5 .cse4 .cse6) (or .cse5 .cse2 .cse6)))) [2021-12-21 13:14:20,121 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 234 257) no Hoare annotation was computed. [2021-12-21 13:14:20,121 INFO L858 garLoopResultBuilder]: For program point L138(lines 138 142) no Hoare annotation was computed. [2021-12-21 13:14:20,121 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 83) no Hoare annotation was computed. [2021-12-21 13:14:20,121 INFO L854 garLoopResultBuilder]: At program point L138-2(lines 134 145) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (= 0 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse4 .cse2 .cse5) (or .cse4 .cse3 .cse5) (or .cse4 .cse1 .cse3) (or .cse4 .cse1 .cse2))) [2021-12-21 13:14:20,122 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 170 178) the Hoare annotation is: true [2021-12-21 13:14:20,122 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 170 178) no Hoare annotation was computed. [2021-12-21 13:14:20,122 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 170 178) no Hoare annotation was computed. [2021-12-21 13:14:20,122 INFO L861 garLoopResultBuilder]: At program point L944(lines 937 946) the Hoare annotation is: true [2021-12-21 13:14:20,122 INFO L854 garLoopResultBuilder]: At program point L106(lines 102 108) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:20,122 INFO L858 garLoopResultBuilder]: For program point L453(lines 452 499) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point L482(lines 482 495) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point L957(lines 957 964) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L858 garLoopResultBuilder]: For program point L957-2(lines 957 964) no Hoare annotation was computed. [2021-12-21 13:14:20,123 INFO L854 garLoopResultBuilder]: At program point L474(line 474) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:20,124 INFO L861 garLoopResultBuilder]: At program point L503(lines 442 507) the Hoare annotation is: true [2021-12-21 13:14:20,124 INFO L854 garLoopResultBuilder]: At program point L437(lines 425 439) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= 0 ~systemActive~0))) (or (and .cse0 (<= 1 ~methaneLevelCritical~0) .cse1 .cse2) (and .cse0 (= ~methaneLevelCritical~0 0) .cse1 .cse2))) [2021-12-21 13:14:20,124 INFO L858 garLoopResultBuilder]: For program point L462(lines 462 468) no Hoare annotation was computed. [2021-12-21 13:14:20,124 INFO L858 garLoopResultBuilder]: For program point L462-1(lines 462 468) no Hoare annotation was computed. [2021-12-21 13:14:20,124 INFO L858 garLoopResultBuilder]: For program point L429(lines 429 435) no Hoare annotation was computed. [2021-12-21 13:14:20,124 INFO L858 garLoopResultBuilder]: For program point L429-1(lines 429 435) no Hoare annotation was computed. [2021-12-21 13:14:20,124 INFO L858 garLoopResultBuilder]: For program point L454(lines 454 458) no Hoare annotation was computed. [2021-12-21 13:14:20,125 INFO L861 garLoopResultBuilder]: At program point L966(lines 947 969) the Hoare annotation is: true [2021-12-21 13:14:20,125 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-21 13:14:20,125 INFO L854 garLoopResultBuilder]: At program point L500(lines 451 501) the Hoare annotation is: false [2021-12-21 13:14:20,125 INFO L858 garLoopResultBuilder]: For program point L488(lines 488 494) no Hoare annotation was computed. [2021-12-21 13:14:20,125 INFO L854 garLoopResultBuilder]: At program point L934(lines 930 936) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:20,125 INFO L854 garLoopResultBuilder]: At program point L488-2(lines 482 495) the Hoare annotation is: (let ((.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse3 (= 0 ~systemActive~0)) (.cse5 (= ~methaneLevelCritical~0 0)) (.cse4 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse4 .cse2) (and .cse0 .cse5 .cse2 .cse3) (and .cse5 .cse4 .cse2))) [2021-12-21 13:14:20,126 INFO L854 garLoopResultBuilder]: At program point L121(lines 116 124) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:20,126 INFO L858 garLoopResultBuilder]: For program point L472(lines 472 478) no Hoare annotation was computed. [2021-12-21 13:14:20,126 INFO L858 garLoopResultBuilder]: For program point L472-1(lines 472 478) no Hoare annotation was computed. [2021-12-21 13:14:20,126 INFO L854 garLoopResultBuilder]: At program point L113(lines 109 115) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:20,126 INFO L854 garLoopResultBuilder]: At program point L497(lines 452 499) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:20,126 INFO L854 garLoopResultBuilder]: At program point L464(line 464) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:20,127 INFO L854 garLoopResultBuilder]: At program point L431(line 431) the Hoare annotation is: (let ((.cse3 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse0 (<= 1 ~methaneLevelCritical~0)) (.cse4 (<= 2 ~waterLevel~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse3 .cse4 .cse2 .cse5) (and .cse3 .cse1 .cse2) (and .cse0 .cse4 .cse2 .cse5))) [2021-12-21 13:14:20,127 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 146 157) no Hoare annotation was computed. [2021-12-21 13:14:20,127 INFO L858 garLoopResultBuilder]: For program point L150-1(lines 146 157) no Hoare annotation was computed. [2021-12-21 13:14:20,127 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 146 157) the Hoare annotation is: (let ((.cse3 (not (= 0 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse2 .cse3) (or .cse5 .cse4 .cse2) (or .cse0 .cse5 .cse1 .cse2))) [2021-12-21 13:14:20,127 INFO L858 garLoopResultBuilder]: For program point L415(lines 415 419) no Hoare annotation was computed. [2021-12-21 13:14:20,127 INFO L858 garLoopResultBuilder]: For program point L415-2(lines 415 419) no Hoare annotation was computed. [2021-12-21 13:14:20,128 INFO L854 garLoopResultBuilder]: At program point L285(line 285) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse2 .cse0 (not (<= 1 ~methaneLevelCritical~0))) (or .cse2 .cse0 .cse1))) [2021-12-21 13:14:20,128 INFO L858 garLoopResultBuilder]: For program point L285-1(lines 266 290) no Hoare annotation was computed. [2021-12-21 13:14:20,128 INFO L858 garLoopResultBuilder]: For program point L215(lines 215 221) no Hoare annotation was computed. [2021-12-21 13:14:20,128 INFO L854 garLoopResultBuilder]: At program point L220(lines 211 224) the Hoare annotation is: (let ((.cse3 (not (= 1 ~systemActive~0))) (.cse1 (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1|)) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (<= 2 ~waterLevel~0))) (and (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or (and .cse0 .cse1 .cse2) .cse3 (and .cse0 .cse2 .cse4) (not (= ~methaneLevelCritical~0 0)))) (or (not (= |old(~pumpRunning~0)| 0)) .cse3 (and .cse1 .cse2) (not (<= 1 ~methaneLevelCritical~0)) (and .cse2 .cse4)))) [2021-12-21 13:14:20,128 INFO L854 garLoopResultBuilder]: At program point L280(line 280) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |processEnvironment__wrappee__methaneQuery_~tmp~1#1| 0)) (.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= ~methaneLevelCritical~0 0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2)) (or (not (= |old(~pumpRunning~0)| 0)) (and .cse1 .cse2) .cse0 (not (<= 1 ~methaneLevelCritical~0))))) [2021-12-21 13:14:20,128 INFO L858 garLoopResultBuilder]: For program point L274(lines 274 282) no Hoare annotation was computed. [2021-12-21 13:14:20,129 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 266 290) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (= ~methaneLevelCritical~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (<= 1 ~methaneLevelCritical~0))))) [2021-12-21 13:14:20,129 INFO L858 garLoopResultBuilder]: For program point L270(lines 270 287) no Hoare annotation was computed. [2021-12-21 13:14:20,129 INFO L858 garLoopResultBuilder]: For program point L332(lines 332 338) no Hoare annotation was computed. [2021-12-21 13:14:20,129 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 266 290) no Hoare annotation was computed. [2021-12-21 13:14:20,129 INFO L854 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0)) (and .cse1 .cse2)) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:20,129 INFO L854 garLoopResultBuilder]: At program point L332-2(lines 325 341) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (<= 2 ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0)) (and (= ~pumpRunning~0 0) .cse1 (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__methaneQuery_activatePump_~tmp~3#1|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:20,129 INFO L858 garLoopResultBuilder]: For program point L330-1(line 330) no Hoare annotation was computed. [2021-12-21 13:14:20,130 INFO L854 garLoopResultBuilder]: At program point L421(lines 406 424) the Hoare annotation is: (let ((.cse7 (= 1 ~systemActive~0))) (let ((.cse0 (not .cse7)) (.cse1 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~1#1| 0)) (.cse3 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0)) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (<= 2 ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse1 .cse2 .cse3) (not (<= 1 ~methaneLevelCritical~0)) (and .cse2 .cse4)) (let ((.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (= ~methaneLevelCritical~0 0))) (or .cse0 (and .cse1 .cse5 .cse2 .cse6 .cse7 .cse3) (not .cse6) (and .cse5 .cse2 .cse6 .cse4 .cse7)))))) [2021-12-21 13:14:20,130 INFO L854 garLoopResultBuilder]: At program point L322(lines 317 324) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0))) (or .cse0 (<= 2 ~waterLevel~0) (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:20,130 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 350 360) the Hoare annotation is: true [2021-12-21 13:14:20,130 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 350 360) no Hoare annotation was computed. [2021-12-21 13:14:20,130 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 350 360) no Hoare annotation was computed. [2021-12-21 13:14:20,130 INFO L861 garLoopResultBuilder]: At program point L355(line 355) the Hoare annotation is: true [2021-12-21 13:14:20,131 INFO L858 garLoopResultBuilder]: For program point L355-1(line 355) no Hoare annotation was computed. [2021-12-21 13:14:20,133 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:20,136 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-21 13:14:20,172 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.12 01:14:20 BoogieIcfgContainer [2021-12-21 13:14:20,175 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-21 13:14:20,176 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-21 13:14:20,177 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-21 13:14:20,177 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-21 13:14:20,177 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:11" (3/4) ... [2021-12-21 13:14:20,180 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-21 13:14:20,185 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-21 13:14:20,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-21 13:14:20,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-21 13:14:20,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-21 13:14:20,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-21 13:14:20,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-21 13:14:20,187 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-21 13:14:20,187 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:20,187 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-21 13:14:20,198 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 49 nodes and edges [2021-12-21 13:14:20,199 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-21 13:14:20,200 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-21 13:14:20,200 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-21 13:14:20,200 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-21 13:14:20,201 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:14:20,201 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:14:20,223 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:20,224 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((((pumpRunning == \old(pumpRunning) || pumpRunning == 0) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) [2021-12-21 13:14:20,225 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel)) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((((!(1 == systemActive) || (tmp == 0 && 2 <= waterLevel)) || (pumpRunning == 0 && tmp == 0)) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel)) && (((((pumpRunning == 0 && tmp == 0) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(0 == systemActive)) [2021-12-21 13:14:20,226 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && \result == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((!(1 == systemActive) || (pumpRunning == 0 && \result == 0)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:20,226 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && 2 <= waterLevel) && methaneLevelCritical <= tmp)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:20,226 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:20,226 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == \old(pumpRunning) && 1 <= \result) && pumpRunning == 0) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (1 <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) [2021-12-21 13:14:20,227 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:20,227 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((tmp___0 == 0 && pumpRunning == 0) && \result == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) && (((!(1 == systemActive) || (((((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) && methaneLevelCritical == 0) && 1 == systemActive) && \result == 0)) || !(methaneLevelCritical == 0)) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methaneLevelCritical == 0) && 2 <= waterLevel) && 1 == systemActive)) [2021-12-21 13:14:20,267 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-21 13:14:20,268 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-21 13:14:20,268 INFO L158 Benchmark]: Toolchain (without parser) took 10183.33ms. Allocated memory was 90.2MB in the beginning and 159.4MB in the end (delta: 69.2MB). Free memory was 57.6MB in the beginning and 112.4MB in the end (delta: -54.8MB). Peak memory consumption was 12.5MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,269 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 90.2MB. Free memory was 47.2MB in the beginning and 47.1MB in the end (delta: 84.0kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-21 13:14:20,269 INFO L158 Benchmark]: CACSL2BoogieTranslator took 397.39ms. Allocated memory is still 90.2MB. Free memory was 57.3MB in the beginning and 57.4MB in the end (delta: -59.4kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,269 INFO L158 Benchmark]: Boogie Procedure Inliner took 42.54ms. Allocated memory is still 90.2MB. Free memory was 57.4MB in the beginning and 54.9MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,270 INFO L158 Benchmark]: Boogie Preprocessor took 23.91ms. Allocated memory is still 90.2MB. Free memory was 54.9MB in the beginning and 53.5MB in the end (delta: 1.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,271 INFO L158 Benchmark]: RCFGBuilder took 480.08ms. Allocated memory was 90.2MB in the beginning and 109.1MB in the end (delta: 18.9MB). Free memory was 53.5MB in the beginning and 81.3MB in the end (delta: -27.7MB). Peak memory consumption was 16.1MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,271 INFO L158 Benchmark]: TraceAbstraction took 9132.55ms. Allocated memory was 109.1MB in the beginning and 159.4MB in the end (delta: 50.3MB). Free memory was 80.8MB in the beginning and 118.7MB in the end (delta: -37.9MB). Peak memory consumption was 89.9MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,272 INFO L158 Benchmark]: Witness Printer took 91.41ms. Allocated memory is still 159.4MB. Free memory was 118.7MB in the beginning and 112.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-21 13:14:20,273 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 90.2MB. Free memory was 47.2MB in the beginning and 47.1MB in the end (delta: 84.0kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 397.39ms. Allocated memory is still 90.2MB. Free memory was 57.3MB in the beginning and 57.4MB in the end (delta: -59.4kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 42.54ms. Allocated memory is still 90.2MB. Free memory was 57.4MB in the beginning and 54.9MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 23.91ms. Allocated memory is still 90.2MB. Free memory was 54.9MB in the beginning and 53.5MB in the end (delta: 1.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 480.08ms. Allocated memory was 90.2MB in the beginning and 109.1MB in the end (delta: 18.9MB). Free memory was 53.5MB in the beginning and 81.3MB in the end (delta: -27.7MB). Peak memory consumption was 16.1MB. Max. memory is 16.1GB. * TraceAbstraction took 9132.55ms. Allocated memory was 109.1MB in the beginning and 159.4MB in the end (delta: 50.3MB). Free memory was 80.8MB in the beginning and 118.7MB in the end (delta: -37.9MB). Peak memory consumption was 89.9MB. Max. memory is 16.1GB. * Witness Printer took 91.41ms. Allocated memory is still 159.4MB. Free memory was 118.7MB in the beginning and 112.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 83]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 100 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.0s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.4s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1607 SdHoareTripleChecker+Valid, 1.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1567 mSDsluCounter, 4171 SdHoareTripleChecker+Invalid, 1.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2777 mSDsCounter, 543 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1766 IncrementalHoareTripleChecker+Invalid, 2309 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 543 mSolverCounterUnsat, 1394 mSDtfsCounter, 1766 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 368 GetRequests, 263 SyntacticMatches, 1 SemanticMatches, 104 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 155 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1049occurred in iteration=8, InterpolantAutomatonStates: 88, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 147 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 2324 PreInvPairs, 2637 NumberOfFragments, 1724 HoareAnnotationTreeSize, 2324 FomulaSimplifications, 1552 FormulaSimplificationTreeSizeReduction, 0.5s HoareSimplificationTime, 45 FomulaSimplificationsInter, 11261 FormulaSimplificationTreeSizeReductionInter, 2.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.6s InterpolantComputationTime, 742 NumberOfCodeBlocks, 742 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 729 ConstructedInterpolants, 0 QuantifiedInterpolants, 1385 SizeOfPredicates, 6 NumberOfNonLiveVariables, 863 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 113/127 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 79]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 325]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && 2 <= waterLevel) && methaneLevelCritical <= tmp)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 211]: Loop Invariant Derived loop invariant: (((((pumpRunning == \old(pumpRunning) && 1 <= \result) && pumpRunning == 0) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (1 <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) - InvariantResult [Line: 406]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((tmp___0 == 0 && pumpRunning == 0) && \result == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) && (((!(1 == systemActive) || (((((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) && methaneLevelCritical == 0) && 1 == systemActive) && \result == 0)) || !(methaneLevelCritical == 0)) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methaneLevelCritical == 0) && 2 <= waterLevel) && 1 == systemActive)) - InvariantResult [Line: 947]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 361]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && \result == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((!(1 == systemActive) || (pumpRunning == 0 && \result == 0)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 876]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 425]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 1 <= methaneLevelCritical) && splverifierCounter == 0) && 0 == systemActive) || (((pumpRunning == 0 && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: 452]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 <= methaneLevelCritical) && splverifierCounter == 0) && 0 == systemActive) || (((pumpRunning == 0 && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive)) || ((methaneLevelCritical == 0 && 1 == systemActive) && splverifierCounter == 0)) || (((pumpRunning == 0 && 1 <= methaneLevelCritical) && 1 == systemActive) && splverifierCounter == 0) - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 53]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel)) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((((!(1 == systemActive) || (tmp == 0 && 2 <= waterLevel)) || (pumpRunning == 0 && tmp == 0)) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel)) && (((((pumpRunning == 0 && tmp == 0) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(0 == systemActive)) - InvariantResult [Line: 886]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 116]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 930]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 134]: Loop Invariant Derived loop invariant: ((((((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 292]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((((pumpRunning == \old(pumpRunning) || pumpRunning == 0) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) - InvariantResult [Line: 442]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 451]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 102]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 RESULT: Ultimate proved your program to be correct! [2021-12-21 13:14:20,341 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE