./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version ff03de63 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash ae2f7a85a5093ad80fd05f69a7d0bbcf9a510999a9154b6f2d8037f035f00930 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-ff03de6 [2021-12-21 13:14:08,884 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-21 13:14:08,885 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-21 13:14:08,934 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-21 13:14:08,935 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-21 13:14:08,936 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-21 13:14:08,936 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-21 13:14:08,938 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-21 13:14:08,943 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-21 13:14:08,944 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-21 13:14:08,945 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-21 13:14:08,946 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-21 13:14:08,947 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-21 13:14:08,949 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-21 13:14:08,950 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-21 13:14:08,955 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-21 13:14:08,956 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-21 13:14:08,956 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-21 13:14:08,957 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-21 13:14:08,958 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-21 13:14:08,959 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-21 13:14:08,960 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-21 13:14:08,961 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-21 13:14:08,961 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-21 13:14:08,963 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-21 13:14:08,963 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-21 13:14:08,963 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-21 13:14:08,964 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-21 13:14:08,964 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-21 13:14:08,965 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-21 13:14:08,965 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-21 13:14:08,966 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-21 13:14:08,966 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-21 13:14:08,967 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-21 13:14:08,967 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-21 13:14:08,968 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-21 13:14:08,968 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-21 13:14:08,968 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-21 13:14:08,969 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-21 13:14:08,969 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-21 13:14:08,970 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-21 13:14:08,970 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-21 13:14:08,989 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-21 13:14:08,990 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-21 13:14:08,990 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-21 13:14:08,990 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-21 13:14:08,991 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-21 13:14:08,991 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-21 13:14:08,991 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-21 13:14:08,991 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-21 13:14:08,992 INFO L138 SettingsManager]: * Use SBE=true [2021-12-21 13:14:08,992 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-21 13:14:08,992 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-21 13:14:08,992 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-21 13:14:08,992 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-21 13:14:08,993 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-21 13:14:08,993 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-21 13:14:08,993 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-21 13:14:08,993 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-21 13:14:08,993 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-21 13:14:08,994 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-21 13:14:08,994 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-21 13:14:08,994 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-21 13:14:08,994 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-21 13:14:08,994 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-21 13:14:08,994 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-21 13:14:08,995 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:14:08,995 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-21 13:14:08,995 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-21 13:14:08,995 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-21 13:14:08,995 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-21 13:14:08,996 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-21 13:14:08,996 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-21 13:14:08,996 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-21 13:14:08,996 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-21 13:14:08,996 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-21 13:14:08,997 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> ae2f7a85a5093ad80fd05f69a7d0bbcf9a510999a9154b6f2d8037f035f00930 [2021-12-21 13:14:09,141 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-21 13:14:09,159 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-21 13:14:09,170 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-21 13:14:09,173 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-21 13:14:09,175 INFO L275 PluginConnector]: CDTParser initialized [2021-12-21 13:14:09,176 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c [2021-12-21 13:14:09,221 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c6ca7d187/734fbdd24987487e82c99023d469090d/FLAGcc8613fa2 [2021-12-21 13:14:09,620 INFO L306 CDTParser]: Found 1 translation units. [2021-12-21 13:14:09,622 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c [2021-12-21 13:14:09,632 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c6ca7d187/734fbdd24987487e82c99023d469090d/FLAGcc8613fa2 [2021-12-21 13:14:09,989 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c6ca7d187/734fbdd24987487e82c99023d469090d [2021-12-21 13:14:09,992 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-21 13:14:09,993 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-21 13:14:09,999 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-21 13:14:09,999 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-21 13:14:10,002 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-21 13:14:10,002 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:14:09" (1/1) ... [2021-12-21 13:14:10,003 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@421b769f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10, skipping insertion in model container [2021-12-21 13:14:10,003 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:14:09" (1/1) ... [2021-12-21 13:14:10,008 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-21 13:14:10,046 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-21 13:14:10,297 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c[17123,17136] [2021-12-21 13:14:10,310 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:14:10,321 INFO L203 MainTranslator]: Completed pre-run [2021-12-21 13:14:10,378 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product48.cil.c[17123,17136] [2021-12-21 13:14:10,380 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:14:10,391 INFO L208 MainTranslator]: Completed translation [2021-12-21 13:14:10,392 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10 WrapperNode [2021-12-21 13:14:10,392 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-21 13:14:10,393 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-21 13:14:10,393 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-21 13:14:10,393 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-21 13:14:10,398 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,422 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,442 INFO L137 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 22, calls inlined = 19, statements flattened = 244 [2021-12-21 13:14:10,443 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-21 13:14:10,443 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-21 13:14:10,443 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-21 13:14:10,443 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-21 13:14:10,451 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,451 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,457 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,457 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,464 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,467 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,468 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,470 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-21 13:14:10,470 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-21 13:14:10,470 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-21 13:14:10,470 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-21 13:14:10,477 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (1/1) ... [2021-12-21 13:14:10,483 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:14:10,491 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:10,513 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-21 13:14:10,530 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-21 13:14:10,540 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-21 13:14:10,540 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:10,541 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-21 13:14:10,541 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-21 13:14:10,542 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-21 13:14:10,542 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-21 13:14:10,542 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-21 13:14:10,542 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-21 13:14:10,542 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-21 13:14:10,542 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-21 13:14:10,542 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-21 13:14:10,609 INFO L234 CfgBuilder]: Building ICFG [2021-12-21 13:14:10,611 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-21 13:14:10,848 INFO L275 CfgBuilder]: Performing block encoding [2021-12-21 13:14:10,852 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-21 13:14:10,853 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-21 13:14:10,854 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:10 BoogieIcfgContainer [2021-12-21 13:14:10,854 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-21 13:14:10,855 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-21 13:14:10,855 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-21 13:14:10,857 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-21 13:14:10,858 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.12 01:14:09" (1/3) ... [2021-12-21 13:14:10,858 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@2de7f31c and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:14:10, skipping insertion in model container [2021-12-21 13:14:10,858 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:14:10" (2/3) ... [2021-12-21 13:14:10,859 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@2de7f31c and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:14:10, skipping insertion in model container [2021-12-21 13:14:10,859 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:10" (3/3) ... [2021-12-21 13:14:10,860 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product48.cil.c [2021-12-21 13:14:10,863 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-21 13:14:10,863 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-21 13:14:10,891 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-21 13:14:10,896 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-21 13:14:10,896 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-21 13:14:10,918 INFO L276 IsEmpty]: Start isEmpty. Operand has 101 states, 74 states have (on average 1.364864864864865) internal successors, (101), 83 states have internal predecessors, (101), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) [2021-12-21 13:14:10,924 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2021-12-21 13:14:10,924 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:10,925 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:10,926 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:10,932 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:10,932 INFO L85 PathProgramCache]: Analyzing trace with hash 1258110476, now seen corresponding path program 1 times [2021-12-21 13:14:10,938 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:10,939 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [617142511] [2021-12-21 13:14:10,939 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:10,940 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,018 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,070 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-21 13:14:11,074 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,083 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,083 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,083 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [617142511] [2021-12-21 13:14:11,084 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [617142511] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,084 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,084 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-21 13:14:11,085 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [296760228] [2021-12-21 13:14:11,086 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,089 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-21 13:14:11,089 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,110 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-21 13:14:11,112 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:14:11,114 INFO L87 Difference]: Start difference. First operand has 101 states, 74 states have (on average 1.364864864864865) internal successors, (101), 83 states have internal predecessors, (101), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,145 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,145 INFO L93 Difference]: Finished difference Result 194 states and 261 transitions. [2021-12-21 13:14:11,146 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-21 13:14:11,147 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2021-12-21 13:14:11,147 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,160 INFO L225 Difference]: With dead ends: 194 [2021-12-21 13:14:11,160 INFO L226 Difference]: Without dead ends: 92 [2021-12-21 13:14:11,164 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:14:11,167 INFO L933 BasicCegarLoop]: 127 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 127 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,168 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 127 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,178 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 92 states. [2021-12-21 13:14:11,201 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 92 to 92. [2021-12-21 13:14:11,202 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 92 states, 67 states have (on average 1.2985074626865671) internal successors, (87), 75 states have internal predecessors, (87), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 12 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-21 13:14:11,217 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 92 states to 92 states and 118 transitions. [2021-12-21 13:14:11,218 INFO L78 Accepts]: Start accepts. Automaton has 92 states and 118 transitions. Word has length 23 [2021-12-21 13:14:11,218 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,219 INFO L470 AbstractCegarLoop]: Abstraction has 92 states and 118 transitions. [2021-12-21 13:14:11,219 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,219 INFO L276 IsEmpty]: Start isEmpty. Operand 92 states and 118 transitions. [2021-12-21 13:14:11,220 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-21 13:14:11,220 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,220 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,220 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-21 13:14:11,221 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,221 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,221 INFO L85 PathProgramCache]: Analyzing trace with hash -1705390326, now seen corresponding path program 1 times [2021-12-21 13:14:11,221 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,222 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1768770610] [2021-12-21 13:14:11,222 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,222 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,246 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,280 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-21 13:14:11,284 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,287 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,287 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,287 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1768770610] [2021-12-21 13:14:11,287 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1768770610] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,287 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,287 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:14:11,287 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [602754153] [2021-12-21 13:14:11,287 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,288 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:14:11,288 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,289 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:14:11,289 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,289 INFO L87 Difference]: Start difference. First operand 92 states and 118 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,304 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,307 INFO L93 Difference]: Finished difference Result 145 states and 185 transitions. [2021-12-21 13:14:11,307 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:14:11,307 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2021-12-21 13:14:11,308 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,310 INFO L225 Difference]: With dead ends: 145 [2021-12-21 13:14:11,311 INFO L226 Difference]: Without dead ends: 83 [2021-12-21 13:14:11,311 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,313 INFO L933 BasicCegarLoop]: 105 mSDtfsCounter, 17 mSDsluCounter, 83 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 188 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,314 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [21 Valid, 188 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,314 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 83 states. [2021-12-21 13:14:11,319 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 83 to 83. [2021-12-21 13:14:11,319 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 83 states, 61 states have (on average 1.3114754098360655) internal successors, (80), 69 states have internal predecessors, (80), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-21 13:14:11,320 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 83 states to 83 states and 106 transitions. [2021-12-21 13:14:11,320 INFO L78 Accepts]: Start accepts. Automaton has 83 states and 106 transitions. Word has length 24 [2021-12-21 13:14:11,320 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,321 INFO L470 AbstractCegarLoop]: Abstraction has 83 states and 106 transitions. [2021-12-21 13:14:11,321 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,321 INFO L276 IsEmpty]: Start isEmpty. Operand 83 states and 106 transitions. [2021-12-21 13:14:11,322 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2021-12-21 13:14:11,322 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,322 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,322 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-21 13:14:11,322 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,323 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,323 INFO L85 PathProgramCache]: Analyzing trace with hash 581187755, now seen corresponding path program 1 times [2021-12-21 13:14:11,323 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,323 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1276242208] [2021-12-21 13:14:11,323 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,324 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,352 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,398 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-21 13:14:11,400 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,406 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,406 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,406 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1276242208] [2021-12-21 13:14:11,407 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1276242208] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,407 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,407 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:14:11,407 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [204268783] [2021-12-21 13:14:11,407 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,407 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:14:11,407 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,409 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:14:11,409 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,409 INFO L87 Difference]: Start difference. First operand 83 states and 106 transitions. Second operand has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 3 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,440 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,441 INFO L93 Difference]: Finished difference Result 233 states and 303 transitions. [2021-12-21 13:14:11,441 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:14:11,441 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 3 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2021-12-21 13:14:11,441 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,442 INFO L225 Difference]: With dead ends: 233 [2021-12-21 13:14:11,443 INFO L226 Difference]: Without dead ends: 157 [2021-12-21 13:14:11,443 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:14:11,444 INFO L933 BasicCegarLoop]: 134 mSDtfsCounter, 98 mSDsluCounter, 94 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 98 SdHoareTripleChecker+Valid, 228 SdHoareTripleChecker+Invalid, 5 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,444 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [98 Valid, 228 Invalid, 5 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:14:11,445 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 157 states. [2021-12-21 13:14:11,456 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 157 to 154. [2021-12-21 13:14:11,457 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 154 states, 111 states have (on average 1.3333333333333333) internal successors, (148), 126 states have internal predecessors, (148), 26 states have call successors, (26), 16 states have call predecessors, (26), 16 states have return successors, (26), 19 states have call predecessors, (26), 26 states have call successors, (26) [2021-12-21 13:14:11,458 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 154 states to 154 states and 200 transitions. [2021-12-21 13:14:11,458 INFO L78 Accepts]: Start accepts. Automaton has 154 states and 200 transitions. Word has length 29 [2021-12-21 13:14:11,458 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,458 INFO L470 AbstractCegarLoop]: Abstraction has 154 states and 200 transitions. [2021-12-21 13:14:11,458 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 3 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,458 INFO L276 IsEmpty]: Start isEmpty. Operand 154 states and 200 transitions. [2021-12-21 13:14:11,459 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-21 13:14:11,460 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,460 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,460 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-21 13:14:11,460 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,460 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,461 INFO L85 PathProgramCache]: Analyzing trace with hash 1535507548, now seen corresponding path program 1 times [2021-12-21 13:14:11,461 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,461 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1735750719] [2021-12-21 13:14:11,461 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,461 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,485 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,521 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:11,523 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,530 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,530 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,531 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1735750719] [2021-12-21 13:14:11,531 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1735750719] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,531 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,531 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:11,531 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1023043294] [2021-12-21 13:14:11,531 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,532 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:11,532 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,532 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:11,532 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:11,533 INFO L87 Difference]: Start difference. First operand 154 states and 200 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,638 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:11,639 INFO L93 Difference]: Finished difference Result 448 states and 591 transitions. [2021-12-21 13:14:11,639 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:11,639 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2021-12-21 13:14:11,639 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:11,642 INFO L225 Difference]: With dead ends: 448 [2021-12-21 13:14:11,642 INFO L226 Difference]: Without dead ends: 301 [2021-12-21 13:14:11,643 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-21 13:14:11,644 INFO L933 BasicCegarLoop]: 116 mSDtfsCounter, 77 mSDsluCounter, 407 mSDsCounter, 0 mSdLazyCounter, 52 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 80 SdHoareTripleChecker+Valid, 523 SdHoareTripleChecker+Invalid, 56 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 52 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:11,644 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [80 Valid, 523 Invalid, 56 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 52 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:11,645 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 301 states. [2021-12-21 13:14:11,670 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 301 to 295. [2021-12-21 13:14:11,676 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 295 states, 210 states have (on average 1.3238095238095238) internal successors, (278), 239 states have internal predecessors, (278), 52 states have call successors, (52), 32 states have call predecessors, (52), 32 states have return successors, (54), 38 states have call predecessors, (54), 52 states have call successors, (54) [2021-12-21 13:14:11,678 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 295 states to 295 states and 384 transitions. [2021-12-21 13:14:11,680 INFO L78 Accepts]: Start accepts. Automaton has 295 states and 384 transitions. Word has length 32 [2021-12-21 13:14:11,680 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:11,680 INFO L470 AbstractCegarLoop]: Abstraction has 295 states and 384 transitions. [2021-12-21 13:14:11,680 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-21 13:14:11,681 INFO L276 IsEmpty]: Start isEmpty. Operand 295 states and 384 transitions. [2021-12-21 13:14:11,682 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2021-12-21 13:14:11,686 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:11,686 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:11,687 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-21 13:14:11,687 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:11,687 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:11,687 INFO L85 PathProgramCache]: Analyzing trace with hash 382867040, now seen corresponding path program 1 times [2021-12-21 13:14:11,687 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:11,688 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [986897487] [2021-12-21 13:14:11,688 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:11,688 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:11,704 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,757 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:11,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,762 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-21 13:14:11,763 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:11,775 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:11,775 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:11,775 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [986897487] [2021-12-21 13:14:11,776 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [986897487] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:11,776 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:11,776 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:11,776 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [475156530] [2021-12-21 13:14:11,776 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:11,776 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:11,777 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:11,777 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:11,777 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:11,777 INFO L87 Difference]: Start difference. First operand 295 states and 384 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:14:12,036 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:12,036 INFO L93 Difference]: Finished difference Result 781 states and 1029 transitions. [2021-12-21 13:14:12,037 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:12,037 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 36 [2021-12-21 13:14:12,037 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:12,043 INFO L225 Difference]: With dead ends: 781 [2021-12-21 13:14:12,043 INFO L226 Difference]: Without dead ends: 493 [2021-12-21 13:14:12,045 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-21 13:14:12,053 INFO L933 BasicCegarLoop]: 96 mSDtfsCounter, 129 mSDsluCounter, 155 mSDsCounter, 0 mSdLazyCounter, 217 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 136 SdHoareTripleChecker+Valid, 251 SdHoareTripleChecker+Invalid, 266 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 217 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:12,053 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [136 Valid, 251 Invalid, 266 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 217 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:12,056 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 493 states. [2021-12-21 13:14:12,086 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 493 to 479. [2021-12-21 13:14:12,089 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 479 states, 346 states have (on average 1.2716763005780347) internal successors, (440), 379 states have internal predecessors, (440), 72 states have call successors, (72), 60 states have call predecessors, (72), 60 states have return successors, (92), 66 states have call predecessors, (92), 72 states have call successors, (92) [2021-12-21 13:14:12,092 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 479 states to 479 states and 604 transitions. [2021-12-21 13:14:12,092 INFO L78 Accepts]: Start accepts. Automaton has 479 states and 604 transitions. Word has length 36 [2021-12-21 13:14:12,093 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:12,093 INFO L470 AbstractCegarLoop]: Abstraction has 479 states and 604 transitions. [2021-12-21 13:14:12,093 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:14:12,093 INFO L276 IsEmpty]: Start isEmpty. Operand 479 states and 604 transitions. [2021-12-21 13:14:12,096 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-21 13:14:12,097 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:12,097 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:12,097 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-21 13:14:12,097 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:12,098 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:12,098 INFO L85 PathProgramCache]: Analyzing trace with hash 839687842, now seen corresponding path program 1 times [2021-12-21 13:14:12,098 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:12,098 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [690410232] [2021-12-21 13:14:12,099 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:12,099 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:12,120 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,147 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:12,148 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,159 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-21 13:14:12,163 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,191 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:12,194 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,198 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:12,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,200 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-21 13:14:12,201 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,203 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:12,203 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:12,203 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [690410232] [2021-12-21 13:14:12,203 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [690410232] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:12,203 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:12,203 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-21 13:14:12,203 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [665630169] [2021-12-21 13:14:12,203 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:12,210 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-21 13:14:12,210 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:12,211 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-21 13:14:12,211 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-21 13:14:12,211 INFO L87 Difference]: Start difference. First operand 479 states and 604 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:12,418 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:12,418 INFO L93 Difference]: Finished difference Result 1065 states and 1376 transitions. [2021-12-21 13:14:12,418 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-21 13:14:12,418 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 59 [2021-12-21 13:14:12,419 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:12,424 INFO L225 Difference]: With dead ends: 1065 [2021-12-21 13:14:12,424 INFO L226 Difference]: Without dead ends: 593 [2021-12-21 13:14:12,425 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-21 13:14:12,427 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 132 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 260 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 133 SdHoareTripleChecker+Valid, 260 SdHoareTripleChecker+Invalid, 320 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 260 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:12,430 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [133 Valid, 260 Invalid, 320 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 260 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:12,431 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 593 states. [2021-12-21 13:14:12,466 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 593 to 571. [2021-12-21 13:14:12,467 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 571 states, 418 states have (on average 1.2392344497607655) internal successors, (518), 451 states have internal predecessors, (518), 80 states have call successors, (80), 60 states have call predecessors, (80), 72 states have return successors, (112), 82 states have call predecessors, (112), 80 states have call successors, (112) [2021-12-21 13:14:12,471 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 571 states to 571 states and 710 transitions. [2021-12-21 13:14:12,471 INFO L78 Accepts]: Start accepts. Automaton has 571 states and 710 transitions. Word has length 59 [2021-12-21 13:14:12,471 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:12,472 INFO L470 AbstractCegarLoop]: Abstraction has 571 states and 710 transitions. [2021-12-21 13:14:12,472 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:12,472 INFO L276 IsEmpty]: Start isEmpty. Operand 571 states and 710 transitions. [2021-12-21 13:14:12,473 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-21 13:14:12,473 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:12,474 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:12,474 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-21 13:14:12,474 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:12,474 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:12,474 INFO L85 PathProgramCache]: Analyzing trace with hash 862320096, now seen corresponding path program 1 times [2021-12-21 13:14:12,475 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:12,475 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1856489091] [2021-12-21 13:14:12,475 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:12,475 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:12,499 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,525 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:12,526 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,529 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-21 13:14:12,538 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,559 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:12,564 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,568 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:12,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,576 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-21 13:14:12,578 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,581 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:12,581 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:12,581 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1856489091] [2021-12-21 13:14:12,582 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1856489091] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:12,582 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:12,582 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:12,582 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1749597474] [2021-12-21 13:14:12,582 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:12,582 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:12,583 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:12,583 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:12,584 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:12,584 INFO L87 Difference]: Start difference. First operand 571 states and 710 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:12,766 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:12,767 INFO L93 Difference]: Finished difference Result 1169 states and 1490 transitions. [2021-12-21 13:14:12,767 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-21 13:14:12,767 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 59 [2021-12-21 13:14:12,767 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:12,770 INFO L225 Difference]: With dead ends: 1169 [2021-12-21 13:14:12,771 INFO L226 Difference]: Without dead ends: 605 [2021-12-21 13:14:12,772 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-21 13:14:12,775 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 133 mSDsluCounter, 132 mSDsCounter, 0 mSdLazyCounter, 196 mSolverCounterSat, 53 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 134 SdHoareTripleChecker+Valid, 220 SdHoareTripleChecker+Invalid, 249 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 53 IncrementalHoareTripleChecker+Valid, 196 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:12,776 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [134 Valid, 220 Invalid, 249 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [53 Valid, 196 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:12,776 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 605 states. [2021-12-21 13:14:12,801 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 605 to 579. [2021-12-21 13:14:12,802 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 579 states, 426 states have (on average 1.2347417840375587) internal successors, (526), 459 states have internal predecessors, (526), 80 states have call successors, (80), 60 states have call predecessors, (80), 72 states have return successors, (112), 82 states have call predecessors, (112), 80 states have call successors, (112) [2021-12-21 13:14:12,804 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 579 states to 579 states and 718 transitions. [2021-12-21 13:14:12,805 INFO L78 Accepts]: Start accepts. Automaton has 579 states and 718 transitions. Word has length 59 [2021-12-21 13:14:12,806 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:12,806 INFO L470 AbstractCegarLoop]: Abstraction has 579 states and 718 transitions. [2021-12-21 13:14:12,810 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-21 13:14:12,810 INFO L276 IsEmpty]: Start isEmpty. Operand 579 states and 718 transitions. [2021-12-21 13:14:12,811 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-21 13:14:12,811 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:12,811 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:12,811 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-21 13:14:12,811 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:12,815 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:12,815 INFO L85 PathProgramCache]: Analyzing trace with hash 1137079710, now seen corresponding path program 1 times [2021-12-21 13:14:12,815 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:12,815 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1239757733] [2021-12-21 13:14:12,815 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:12,815 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:12,829 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,857 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:14:12,859 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,863 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-21 13:14:12,867 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,887 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:12,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:12,895 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,899 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-21 13:14:12,899 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:12,901 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:14:12,901 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:12,901 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1239757733] [2021-12-21 13:14:12,901 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1239757733] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:12,901 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:12,901 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:14:12,902 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [732119608] [2021-12-21 13:14:12,902 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:12,902 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:14:12,902 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:12,903 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:14:12,903 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:14:12,903 INFO L87 Difference]: Start difference. First operand 579 states and 718 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-21 13:14:13,170 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:13,171 INFO L93 Difference]: Finished difference Result 1643 states and 2124 transitions. [2021-12-21 13:14:13,171 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-21 13:14:13,171 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) Word has length 59 [2021-12-21 13:14:13,172 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:13,176 INFO L225 Difference]: With dead ends: 1643 [2021-12-21 13:14:13,176 INFO L226 Difference]: Without dead ends: 1071 [2021-12-21 13:14:13,178 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 14 SyntacticMatches, 1 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-21 13:14:13,179 INFO L933 BasicCegarLoop]: 136 mSDtfsCounter, 335 mSDsluCounter, 145 mSDsCounter, 0 mSdLazyCounter, 254 mSolverCounterSat, 142 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 338 SdHoareTripleChecker+Valid, 281 SdHoareTripleChecker+Invalid, 396 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 142 IncrementalHoareTripleChecker+Valid, 254 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:13,179 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [338 Valid, 281 Invalid, 396 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [142 Valid, 254 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:13,180 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1071 states. [2021-12-21 13:14:13,217 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1071 to 1059. [2021-12-21 13:14:13,219 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1059 states, 786 states have (on average 1.213740458015267) internal successors, (954), 837 states have internal predecessors, (954), 142 states have call successors, (142), 126 states have call predecessors, (142), 130 states have return successors, (228), 140 states have call predecessors, (228), 142 states have call successors, (228) [2021-12-21 13:14:13,222 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1059 states to 1059 states and 1324 transitions. [2021-12-21 13:14:13,223 INFO L78 Accepts]: Start accepts. Automaton has 1059 states and 1324 transitions. Word has length 59 [2021-12-21 13:14:13,224 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:13,224 INFO L470 AbstractCegarLoop]: Abstraction has 1059 states and 1324 transitions. [2021-12-21 13:14:13,224 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-21 13:14:13,224 INFO L276 IsEmpty]: Start isEmpty. Operand 1059 states and 1324 transitions. [2021-12-21 13:14:13,226 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2021-12-21 13:14:13,226 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:13,227 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:13,227 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-21 13:14:13,227 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:13,227 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:13,227 INFO L85 PathProgramCache]: Analyzing trace with hash -67517000, now seen corresponding path program 1 times [2021-12-21 13:14:13,228 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:13,228 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [140556155] [2021-12-21 13:14:13,228 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:13,228 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:13,239 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,265 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:13,266 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,276 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-21 13:14:13,277 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,285 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-21 13:14:13,288 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,314 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:13,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,345 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:13,347 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,357 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 54 [2021-12-21 13:14:13,358 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,359 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-21 13:14:13,359 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:13,359 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [140556155] [2021-12-21 13:14:13,359 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [140556155] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-21 13:14:13,359 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [272522066] [2021-12-21 13:14:13,359 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:13,360 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:13,360 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:13,361 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-21 13:14:13,361 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-21 13:14:13,428 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:13,430 INFO L263 TraceCheckSpWp]: Trace formula consists of 385 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-21 13:14:13,434 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-21 13:14:13,694 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:14:13,695 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-21 13:14:13,695 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [272522066] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:13,695 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-21 13:14:13,695 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [14] total 20 [2021-12-21 13:14:13,696 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1812984406] [2021-12-21 13:14:13,696 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:13,696 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:13,696 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:13,696 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:13,697 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=50, Invalid=330, Unknown=0, NotChecked=0, Total=380 [2021-12-21 13:14:13,697 INFO L87 Difference]: Start difference. First operand 1059 states and 1324 transitions. Second operand has 8 states, 8 states have (on average 6.25) internal successors, (50), 6 states have internal predecessors, (50), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-21 13:14:13,800 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:13,800 INFO L93 Difference]: Finished difference Result 2069 states and 2599 transitions. [2021-12-21 13:14:13,801 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:13,801 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.25) internal successors, (50), 6 states have internal predecessors, (50), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) Word has length 63 [2021-12-21 13:14:13,801 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:13,805 INFO L225 Difference]: With dead ends: 2069 [2021-12-21 13:14:13,806 INFO L226 Difference]: Without dead ends: 1017 [2021-12-21 13:14:13,808 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 84 GetRequests, 65 SyntacticMatches, 1 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 20 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=50, Invalid=330, Unknown=0, NotChecked=0, Total=380 [2021-12-21 13:14:13,810 INFO L933 BasicCegarLoop]: 193 mSDtfsCounter, 71 mSDsluCounter, 421 mSDsCounter, 0 mSdLazyCounter, 169 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 75 SdHoareTripleChecker+Valid, 614 SdHoareTripleChecker+Invalid, 172 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 169 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:13,810 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [75 Valid, 614 Invalid, 172 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 169 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:13,811 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1017 states. [2021-12-21 13:14:13,856 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1017 to 1013. [2021-12-21 13:14:13,858 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1013 states, 750 states have (on average 1.2) internal successors, (900), 799 states have internal predecessors, (900), 138 states have call successors, (138), 122 states have call predecessors, (138), 124 states have return successors, (200), 134 states have call predecessors, (200), 138 states have call successors, (200) [2021-12-21 13:14:13,862 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1013 states to 1013 states and 1238 transitions. [2021-12-21 13:14:13,863 INFO L78 Accepts]: Start accepts. Automaton has 1013 states and 1238 transitions. Word has length 63 [2021-12-21 13:14:13,863 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:13,863 INFO L470 AbstractCegarLoop]: Abstraction has 1013 states and 1238 transitions. [2021-12-21 13:14:13,863 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.25) internal successors, (50), 6 states have internal predecessors, (50), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-21 13:14:13,863 INFO L276 IsEmpty]: Start isEmpty. Operand 1013 states and 1238 transitions. [2021-12-21 13:14:13,865 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 91 [2021-12-21 13:14:13,865 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:13,866 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:13,884 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-21 13:14:14,079 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:14,080 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:14,080 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:14,080 INFO L85 PathProgramCache]: Analyzing trace with hash -1120995157, now seen corresponding path program 1 times [2021-12-21 13:14:14,080 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:14,080 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [306572539] [2021-12-21 13:14:14,080 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:14,080 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:14,088 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,108 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:14,109 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,114 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:14:14,117 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,131 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-21 13:14:14,134 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,141 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:14,142 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,143 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:14,144 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,145 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-21 13:14:14,146 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,150 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2021-12-21 13:14:14,151 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,154 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 81 [2021-12-21 13:14:14,155 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,157 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-21 13:14:14,157 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:14,158 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [306572539] [2021-12-21 13:14:14,158 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [306572539] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:14,158 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:14:14,158 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-21 13:14:14,158 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2015451869] [2021-12-21 13:14:14,158 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:14,159 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:14,159 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:14,159 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:14,159 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-21 13:14:14,159 INFO L87 Difference]: Start difference. First operand 1013 states and 1238 transitions. Second operand has 8 states, 8 states have (on average 8.625) internal successors, (69), 4 states have internal predecessors, (69), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-21 13:14:14,415 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:14,415 INFO L93 Difference]: Finished difference Result 1838 states and 2253 transitions. [2021-12-21 13:14:14,415 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-21 13:14:14,415 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 8.625) internal successors, (69), 4 states have internal predecessors, (69), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) Word has length 90 [2021-12-21 13:14:14,416 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:14,419 INFO L225 Difference]: With dead ends: 1838 [2021-12-21 13:14:14,419 INFO L226 Difference]: Without dead ends: 832 [2021-12-21 13:14:14,422 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 20 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=68, Invalid=172, Unknown=0, NotChecked=0, Total=240 [2021-12-21 13:14:14,422 INFO L933 BasicCegarLoop]: 124 mSDtfsCounter, 406 mSDsluCounter, 154 mSDsCounter, 0 mSdLazyCounter, 264 mSolverCounterSat, 191 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 416 SdHoareTripleChecker+Valid, 278 SdHoareTripleChecker+Invalid, 455 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 191 IncrementalHoareTripleChecker+Valid, 264 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:14,423 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [416 Valid, 278 Invalid, 455 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [191 Valid, 264 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:14:14,423 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 832 states. [2021-12-21 13:14:14,456 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 832 to 800. [2021-12-21 13:14:14,457 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 800 states, 594 states have (on average 1.1835016835016836) internal successors, (703), 640 states have internal predecessors, (703), 109 states have call successors, (109), 86 states have call predecessors, (109), 96 states have return successors, (158), 107 states have call predecessors, (158), 109 states have call successors, (158) [2021-12-21 13:14:14,460 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 800 states to 800 states and 970 transitions. [2021-12-21 13:14:14,461 INFO L78 Accepts]: Start accepts. Automaton has 800 states and 970 transitions. Word has length 90 [2021-12-21 13:14:14,461 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:14,461 INFO L470 AbstractCegarLoop]: Abstraction has 800 states and 970 transitions. [2021-12-21 13:14:14,461 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 8.625) internal successors, (69), 4 states have internal predecessors, (69), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-21 13:14:14,462 INFO L276 IsEmpty]: Start isEmpty. Operand 800 states and 970 transitions. [2021-12-21 13:14:14,463 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 109 [2021-12-21 13:14:14,463 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:14:14,463 INFO L514 BasicCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:14,464 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-21 13:14:14,464 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:14:14,464 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:14:14,464 INFO L85 PathProgramCache]: Analyzing trace with hash -849910869, now seen corresponding path program 1 times [2021-12-21 13:14:14,464 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:14:14,464 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [696264772] [2021-12-21 13:14:14,465 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:14,465 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:14:14,473 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,504 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-21 13:14:14,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-21 13:14:14,514 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,520 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-21 13:14:14,522 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-21 13:14:14,526 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,528 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:14,529 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,530 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-21 13:14:14,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,536 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2021-12-21 13:14:14,539 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,547 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2021-12-21 13:14:14,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,579 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:14:14,580 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,589 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 89 [2021-12-21 13:14:14,590 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-21 13:14:14,592 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,593 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2021-12-21 13:14:14,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,594 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 16 proven. 5 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2021-12-21 13:14:14,594 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:14:14,594 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [696264772] [2021-12-21 13:14:14,594 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [696264772] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-21 13:14:14,594 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1739597157] [2021-12-21 13:14:14,595 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:14:14,595 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:14:14,595 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:14:14,596 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-21 13:14:14,597 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-21 13:14:14,668 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:14:14,670 INFO L263 TraceCheckSpWp]: Trace formula consists of 487 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-21 13:14:14,672 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-21 13:14:14,869 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-21 13:14:14,869 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-21 13:14:14,869 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1739597157] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:14:14,869 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-21 13:14:14,870 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [14] total 19 [2021-12-21 13:14:14,870 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [951072038] [2021-12-21 13:14:14,870 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:14:14,870 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:14:14,870 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:14:14,870 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:14:14,870 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=294, Unknown=0, NotChecked=0, Total=342 [2021-12-21 13:14:14,871 INFO L87 Difference]: Start difference. First operand 800 states and 970 transitions. Second operand has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-21 13:14:14,981 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:14:14,981 INFO L93 Difference]: Finished difference Result 1386 states and 1704 transitions. [2021-12-21 13:14:14,981 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:14:14,981 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) Word has length 108 [2021-12-21 13:14:14,982 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:14:14,982 INFO L225 Difference]: With dead ends: 1386 [2021-12-21 13:14:14,982 INFO L226 Difference]: Without dead ends: 0 [2021-12-21 13:14:14,985 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 143 GetRequests, 124 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 43 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=60, Invalid=360, Unknown=0, NotChecked=0, Total=420 [2021-12-21 13:14:14,985 INFO L933 BasicCegarLoop]: 192 mSDtfsCounter, 76 mSDsluCounter, 862 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 80 SdHoareTripleChecker+Valid, 1054 SdHoareTripleChecker+Invalid, 128 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:14:14,986 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [80 Valid, 1054 Invalid, 128 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:14:14,986 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-21 13:14:14,986 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-21 13:14:14,986 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-21 13:14:14,986 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-21 13:14:14,986 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 108 [2021-12-21 13:14:14,987 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:14:14,987 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-21 13:14:14,987 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-21 13:14:14,987 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-21 13:14:14,987 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-21 13:14:14,989 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-21 13:14:15,009 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-21 13:14:15,206 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-21 13:14:15,208 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-21 13:14:17,944 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 762 769) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (not (<= 2 ~waterLevel~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse5 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse4 .cse5) (or .cse0 .cse1 .cse4) (or .cse0 .cse3 .cse2 .cse5))) [2021-12-21 13:14:17,944 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 762 769) no Hoare annotation was computed. [2021-12-21 13:14:17,944 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 762 769) no Hoare annotation was computed. [2021-12-21 13:14:17,944 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 678 684) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 678 684) the Hoare annotation is: true [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 83 94) the Hoare annotation is: (let ((.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse5 (not (<= 1 |old(~methaneLevelCritical~0)|)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse2 .cse4) (or .cse3 .cse2 .cse5 .cse4) (or .cse3 .cse1 .cse2 .cse5))) [2021-12-21 13:14:17,945 INFO L858 garLoopResultBuilder]: For program point L87-1(lines 83 94) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 83 94) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L874(lines 869 876) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1) (or .cse2 .cse3 .cse4) (or .cse2 .cse1 .cse4) (or .cse0 .cse3))) [2021-12-21 13:14:17,945 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 654 677) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L726(line 726) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse0 .cse2) (or .cse3 .cse1 .cse4) (or .cse3 .cse2 .cse4) (or .cse3 .cse0 .cse1))) [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L627(line 627) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and .cse7 .cse6)) (.cse3 (not (= 0 ~systemActive~0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse0 .cse5 .cse2 .cse6) (or .cse7 .cse5 .cse2) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse7 .cse5 (<= 2 ~waterLevel~0) .cse4) (or .cse0 .cse5 .cse4 .cse6)))) [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L722(line 722) the Hoare annotation is: (let ((.cse4 (not (= 0 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse2 .cse4) (or .cse3 .cse5 .cse4) (or .cse3 .cse1 .cse5) (or .cse3 .cse1 .cse2) (or .cse1 .cse5 (and .cse0 (<= 1 |timeShift_processEnvironment_~tmp~6#1|))))) [2021-12-21 13:14:17,945 INFO L858 garLoopResultBuilder]: For program point L627-1(line 627) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L718(line 718) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (= 0 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse4 .cse2 .cse5) (or .cse4 .cse3 .cse5) (or .cse4 .cse1 .cse3) (or .cse4 .cse1 .cse2))) [2021-12-21 13:14:17,945 INFO L858 garLoopResultBuilder]: For program point L718-1(line 718) no Hoare annotation was computed. [2021-12-21 13:14:17,945 INFO L854 garLoopResultBuilder]: At program point L731(line 731) the Hoare annotation is: (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse1 .cse4) (or .cse3 .cse5 .cse4) (or .cse0 .cse5 .cse2))) [2021-12-21 13:14:17,946 INFO L854 garLoopResultBuilder]: At program point L731-1(lines 712 736) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (not (= 0 ~systemActive~0))) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 .cse2) (or .cse0 .cse5 .cse6) (or .cse0 .cse2 .cse6) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4 .cse1 (<= 2 ~waterLevel~0) .cse5) (or .cse0 .cse1 .cse5 .cse3))) [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L665-1(lines 665 671) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L63(lines 63 67) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L854 garLoopResultBuilder]: At program point L63-2(lines 59 70) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (= 0 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse4 .cse2 .cse5) (or .cse4 .cse3 .cse5) (or .cse4 .cse1 .cse3) (or .cse4 .cse1 .cse2))) [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L633(lines 633 639) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L629(lines 629 642) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L854 garLoopResultBuilder]: At program point L629-1(lines 621 645) the Hoare annotation is: (let ((.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= 0 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse7 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~4#1| 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse0 .cse5 .cse3 .cse2) (or .cse1 .cse5 .cse3) (or .cse0 .cse6 (and .cse1 .cse7 .cse2) .cse4) (or .cse5 .cse6 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse7) (and .cse1 .cse7) (and (<= 2 ~waterLevel~0) .cse7)) (or .cse0 .cse5 .cse6 .cse2))) [2021-12-21 13:14:17,946 INFO L854 garLoopResultBuilder]: At program point L786(lines 781 789) the Hoare annotation is: (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= 0 ~systemActive~0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse7 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse2 (and .cse4 .cse5 .cse3) .cse6) (or .cse1 (and .cse4 .cse5) .cse2) (or .cse0 .cse7 .cse6) (or .cse1 .cse7))) [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L658-1(lines 657 676) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L720(lines 720 728) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 654 677) the Hoare annotation is: (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and (= ~pumpRunning~0 0) .cse7)) (.cse3 (not (= 0 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse7))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse5 .cse4 .cse6) (or .cse5 .cse2 .cse6)))) [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L716(lines 716 733) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 654 677) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point L873(line 873) no Hoare annotation was computed. [2021-12-21 13:14:17,946 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 873) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point L163-2(lines 163 177) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 153 182) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point L159(line 159) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L159-1(line 159) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 153 182) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point L178(lines 153 182) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L174(line 174) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L167(lines 167 171) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point L167-1(lines 167 171) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L164(line 164) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 95 103) the Hoare annotation is: true [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 95 103) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 95 103) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L898-1(lines 898 904) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L854 garLoopResultBuilder]: At program point L865(lines 860 867) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 1 ~methaneLevelCritical~0) .cse0 .cse1) (and (= ~methaneLevelCritical~0 0) .cse0 .cse1))) [2021-12-21 13:14:17,947 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 894) no Hoare annotation was computed. [2021-12-21 13:14:17,947 INFO L854 garLoopResultBuilder]: At program point L857(lines 845 859) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= 0 ~systemActive~0))) (or (and .cse0 (<= 1 ~methaneLevelCritical~0) .cse1 .cse2) (and .cse0 (= ~methaneLevelCritical~0 0) .cse1 .cse2))) [2021-12-21 13:14:17,947 INFO L854 garLoopResultBuilder]: At program point L977(lines 972 980) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L849(lines 849 855) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L849-1(lines 849 855) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L854 garLoopResultBuilder]: At program point L969(lines 965 971) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L239(lines 239 246) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L861 garLoopResultBuilder]: At program point L941(lines 878 945) the Hoare annotation is: true [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L239-2(lines 239 246) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L908(lines 908 914) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point L908-1(lines 908 914) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L854 garLoopResultBuilder]: At program point L900(line 900) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:17,948 INFO L854 garLoopResultBuilder]: At program point L962(lines 958 964) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:17,948 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-21 13:14:17,948 INFO L861 garLoopResultBuilder]: At program point L223(lines 216 225) the Hoare annotation is: true [2021-12-21 13:14:17,948 INFO L861 garLoopResultBuilder]: At program point L248(lines 229 251) the Hoare annotation is: true [2021-12-21 13:14:17,948 INFO L854 garLoopResultBuilder]: At program point L851(line 851) the Hoare annotation is: (let ((.cse3 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse0 (<= 1 ~methaneLevelCritical~0)) (.cse4 (<= 2 ~waterLevel~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse3 .cse4 .cse2 .cse5) (and .cse3 .cse1 .cse2) (and .cse0 .cse4 .cse2 .cse5))) [2021-12-21 13:14:17,948 INFO L854 garLoopResultBuilder]: At program point L938(lines 887 939) the Hoare annotation is: false [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L926(lines 926 932) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L926-2(lines 918 933) the Hoare annotation is: (let ((.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse3 (= 0 ~systemActive~0)) (.cse5 (= ~methaneLevelCritical~0 0)) (.cse4 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse4 .cse2) (and .cse0 .cse5 .cse2 .cse3) (and .cse5 .cse4 .cse2))) [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L889(lines 888 937) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L918(lines 918 933) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L212(lines 208 214) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L910(line 910) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L935(lines 888 937) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2 .cse3) (and .cse4 .cse5 .cse2) (and .cse0 .cse1 .cse5 .cse2))) [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L898(lines 898 904) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 71 82) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L75-1(lines 71 82) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 71 82) the Hoare annotation is: (let ((.cse3 (not (= 0 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse2 .cse3) (or .cse5 .cse4 .cse2) (or .cse0 .cse5 .cse1 .cse2))) [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L700(line 700) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |processEnvironment__wrappee__methaneQuery_~tmp~5#1| 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse1 .cse2) (not (<= 1 ~methaneLevelCritical~0))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L694(lines 694 702) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L690(lines 690 707) no Hoare annotation was computed. [2021-12-21 13:14:17,949 INFO L854 garLoopResultBuilder]: At program point L145(lines 136 149) the Hoare annotation is: (let ((.cse3 (not (= 1 ~systemActive~0))) (.cse1 (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1|)) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (<= 2 ~waterLevel~0))) (and (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or (and .cse0 .cse1 .cse2) .cse3 (and .cse0 .cse2 .cse4) (not (= ~methaneLevelCritical~0 0)))) (or (not (= |old(~pumpRunning~0)| 0)) .cse3 (and .cse1 .cse2) (not (<= 1 ~methaneLevelCritical~0)) (and .cse2 .cse4)))) [2021-12-21 13:14:17,949 INFO L858 garLoopResultBuilder]: For program point L752(lines 752 758) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point L750(line 750) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0)) (and .cse1 .cse2)) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point L752-2(lines 745 761) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (<= 2 ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0)) (and (= ~pumpRunning~0 0) (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__methaneQuery_activatePump_~tmp~7#1|) .cse1)) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point L750-1(line 750) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point L841(lines 826 844) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse4 (<= 2 ~waterLevel~0)) (.cse1 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~1#1| 0)) (.cse2 (= ~pumpRunning~0 0)) (.cse3 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse1 .cse2 .cse3) (not (<= 1 ~methaneLevelCritical~0)) (and .cse2 .cse4)) (let ((.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or .cse0 (and .cse5 .cse2 .cse4) (and .cse1 .cse5 .cse2 .cse3) (not (= ~methaneLevelCritical~0 0)))))) [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point L742(lines 737 744) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 ~methaneLevelCritical~0))) (or .cse0 (<= 2 ~waterLevel~0) (not (= ~methaneLevelCritical~0 0))))) [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point L835(lines 835 839) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point L835-2(lines 835 839) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point L705(line 705) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse2 .cse0 (not (<= 1 ~methaneLevelCritical~0))) (or .cse2 .cse0 .cse1))) [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point L705-1(lines 686 710) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 686 710) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (= ~methaneLevelCritical~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (<= 1 ~methaneLevelCritical~0))))) [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point L140(lines 140 146) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 686 710) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 770 780) the Hoare annotation is: true [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 770 780) no Hoare annotation was computed. [2021-12-21 13:14:17,950 INFO L861 garLoopResultBuilder]: At program point L775(line 775) the Hoare annotation is: true [2021-12-21 13:14:17,950 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 770 780) no Hoare annotation was computed. [2021-12-21 13:14:17,951 INFO L858 garLoopResultBuilder]: For program point L775-1(line 775) no Hoare annotation was computed. [2021-12-21 13:14:17,953 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:14:17,953 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-21 13:14:17,986 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.12 01:14:17 BoogieIcfgContainer [2021-12-21 13:14:17,986 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-21 13:14:17,986 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-21 13:14:17,986 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-21 13:14:17,987 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-21 13:14:17,987 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:14:10" (3/4) ... [2021-12-21 13:14:17,989 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-21 13:14:17,997 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-21 13:14:18,007 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-21 13:14:18,008 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-21 13:14:18,008 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-21 13:14:18,008 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-21 13:14:18,009 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-21 13:14:18,009 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:14:18,009 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:14:18,023 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,024 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((((pumpRunning == \old(pumpRunning) || pumpRunning == 0) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel)) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && tmp == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == 0)) || (pumpRunning == 0 && tmp == 0)) || (2 <= waterLevel && tmp == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && \result == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((!(1 == systemActive) || (pumpRunning == 0 && \result == 0)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && methaneLevelCritical <= tmp) && 2 <= waterLevel)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == \old(pumpRunning) && 1 <= \result) && pumpRunning == 0) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (1 <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) [2021-12-21 13:14:18,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,026 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((tmp___0 == 0 && pumpRunning == 0) && \result == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || (((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) && \result == 0)) || !(methaneLevelCritical == 0)) [2021-12-21 13:14:18,051 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-21 13:14:18,051 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-21 13:14:18,051 INFO L158 Benchmark]: Toolchain (without parser) took 8058.14ms. Allocated memory was 88.1MB in the beginning and 176.2MB in the end (delta: 88.1MB). Free memory was 54.2MB in the beginning and 101.2MB in the end (delta: -47.0MB). Peak memory consumption was 41.6MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,052 INFO L158 Benchmark]: CDTParser took 0.18ms. Allocated memory is still 88.1MB. Free memory was 60.5MB in the beginning and 60.5MB in the end (delta: 30.4kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-21 13:14:18,052 INFO L158 Benchmark]: CACSL2BoogieTranslator took 393.14ms. Allocated memory was 88.1MB in the beginning and 115.3MB in the end (delta: 27.3MB). Free memory was 54.0MB in the beginning and 84.1MB in the end (delta: -30.1MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,052 INFO L158 Benchmark]: Boogie Procedure Inliner took 49.88ms. Allocated memory is still 115.3MB. Free memory was 84.1MB in the beginning and 81.5MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,052 INFO L158 Benchmark]: Boogie Preprocessor took 26.54ms. Allocated memory is still 115.3MB. Free memory was 81.5MB in the beginning and 80.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,053 INFO L158 Benchmark]: RCFGBuilder took 383.76ms. Allocated memory is still 115.3MB. Free memory was 80.0MB in the beginning and 63.0MB in the end (delta: 17.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,053 INFO L158 Benchmark]: TraceAbstraction took 7130.94ms. Allocated memory was 115.3MB in the beginning and 176.2MB in the end (delta: 60.8MB). Free memory was 63.0MB in the beginning and 107.5MB in the end (delta: -44.4MB). Peak memory consumption was 81.5MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,053 INFO L158 Benchmark]: Witness Printer took 64.71ms. Allocated memory is still 176.2MB. Free memory was 107.5MB in the beginning and 101.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-21 13:14:18,054 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.18ms. Allocated memory is still 88.1MB. Free memory was 60.5MB in the beginning and 60.5MB in the end (delta: 30.4kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 393.14ms. Allocated memory was 88.1MB in the beginning and 115.3MB in the end (delta: 27.3MB). Free memory was 54.0MB in the beginning and 84.1MB in the end (delta: -30.1MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 49.88ms. Allocated memory is still 115.3MB. Free memory was 84.1MB in the beginning and 81.5MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 26.54ms. Allocated memory is still 115.3MB. Free memory was 81.5MB in the beginning and 80.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 383.76ms. Allocated memory is still 115.3MB. Free memory was 80.0MB in the beginning and 63.0MB in the end (delta: 17.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7130.94ms. Allocated memory was 115.3MB in the beginning and 176.2MB in the end (delta: 60.8MB). Free memory was 63.0MB in the beginning and 107.5MB in the end (delta: -44.4MB). Peak memory consumption was 81.5MB. Max. memory is 16.1GB. * Witness Printer took 64.71ms. Allocated memory is still 176.2MB. Free memory was 107.5MB in the beginning and 101.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 873]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 101 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.1s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.7s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.7s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1511 SdHoareTripleChecker+Valid, 1.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1474 mSDsluCounter, 4024 SdHoareTripleChecker+Invalid, 0.8s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2627 mSDsCounter, 509 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1539 IncrementalHoareTripleChecker+Invalid, 2048 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 509 mSolverCounterUnsat, 1397 mSDtfsCounter, 1539 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 364 GetRequests, 267 SyntacticMatches, 2 SemanticMatches, 95 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 122 ImplicationChecksByTransitivity, 0.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1059occurred in iteration=8, InterpolantAutomatonStates: 80, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 11 MinimizatonAttempts, 119 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 46 LocationsWithAnnotation, 2613 PreInvPairs, 2936 NumberOfFragments, 1733 HoareAnnotationTreeSize, 2613 FomulaSimplifications, 1656 FormulaSimplificationTreeSizeReduction, 0.4s HoareSimplificationTime, 46 FomulaSimplificationsInter, 11011 FormulaSimplificationTreeSizeReductionInter, 2.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 753 NumberOfCodeBlocks, 753 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 740 ConstructedInterpolants, 0 QuantifiedInterpolants, 1289 SizeOfPredicates, 6 NumberOfNonLiveVariables, 872 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 123/130 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 860]: Loop Invariant Derived loop invariant: ((1 <= methaneLevelCritical && 1 == systemActive) && splverifierCounter == 0) || ((methaneLevelCritical == 0 && 1 == systemActive) && splverifierCounter == 0) - InvariantResult [Line: 972]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 136]: Loop Invariant Derived loop invariant: (((((pumpRunning == \old(pumpRunning) && 1 <= \result) && pumpRunning == 0) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (1 <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) - InvariantResult [Line: 163]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 888]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 <= methaneLevelCritical) && splverifierCounter == 0) && 0 == systemActive) || (((pumpRunning == 0 && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive)) || ((methaneLevelCritical == 0 && 1 == systemActive) && splverifierCounter == 0)) || (((pumpRunning == 0 && 1 <= methaneLevelCritical) && 1 == systemActive) && splverifierCounter == 0) - InvariantResult [Line: 878]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 781]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && \result == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((!(1 == systemActive) || (pumpRunning == 0 && \result == 0)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 208]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 737]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 621]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel)) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && tmp == 0) && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == 0)) || (pumpRunning == 0 && tmp == 0)) || (2 <= waterLevel && tmp == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) - InvariantResult [Line: 958]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 745]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || ((pumpRunning == 0 && methaneLevelCritical <= tmp) && 2 <= waterLevel)) && ((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 826]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((tmp___0 == 0 && pumpRunning == 0) && \result == 0)) || !(1 <= methaneLevelCritical)) || (pumpRunning == 0 && 2 <= waterLevel)) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel)) || (((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) && \result == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 153]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 887]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 59]: Loop Invariant Derived loop invariant: ((((((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 229]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 845]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 1 <= methaneLevelCritical) && splverifierCounter == 0) && 0 == systemActive) || (((pumpRunning == 0 && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: 965]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 216]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 712]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || \old(waterLevel) == waterLevel) && ((pumpRunning == 0 || !(1 == systemActive)) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && ((((pumpRunning == \old(pumpRunning) || pumpRunning == 0) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) - InvariantResult [Line: 869]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || !(0 == systemActive))) && (!(1 == systemActive) || !(methaneLevelCritical == 0)) RESULT: Ultimate proved your program to be correct! [2021-12-21 13:14:18,092 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE