./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version ff03de63 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 76f5874bdc2210da6be360b9991ed804689b1623a0180577df5607e0ad5d02da --- Real Ultimate output --- This is Ultimate 0.2.2-dev-ff03de6 [2021-12-21 13:16:48,256 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-21 13:16:48,258 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-21 13:16:48,321 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-21 13:16:48,321 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-21 13:16:48,324 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-21 13:16:48,325 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-21 13:16:48,327 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-21 13:16:48,329 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-21 13:16:48,333 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-21 13:16:48,334 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-21 13:16:48,335 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-21 13:16:48,335 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-21 13:16:48,337 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-21 13:16:48,338 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-21 13:16:48,341 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-21 13:16:48,342 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-21 13:16:48,342 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-21 13:16:48,344 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-21 13:16:48,348 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-21 13:16:48,349 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-21 13:16:48,350 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-21 13:16:48,351 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-21 13:16:48,352 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-21 13:16:48,355 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-21 13:16:48,355 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-21 13:16:48,355 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-21 13:16:48,357 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-21 13:16:48,357 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-21 13:16:48,357 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-21 13:16:48,358 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-21 13:16:48,358 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-21 13:16:48,359 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-21 13:16:48,360 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-21 13:16:48,361 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-21 13:16:48,361 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-21 13:16:48,362 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-21 13:16:48,362 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-21 13:16:48,362 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-21 13:16:48,362 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-21 13:16:48,363 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-21 13:16:48,364 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-21 13:16:48,390 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-21 13:16:48,392 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-21 13:16:48,392 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-21 13:16:48,392 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-21 13:16:48,393 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-21 13:16:48,393 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-21 13:16:48,393 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-21 13:16:48,393 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-21 13:16:48,394 INFO L138 SettingsManager]: * Use SBE=true [2021-12-21 13:16:48,394 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-21 13:16:48,394 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-21 13:16:48,395 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-21 13:16:48,396 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-21 13:16:48,396 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:16:48,397 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-21 13:16:48,397 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-21 13:16:48,398 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-21 13:16:48,399 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-21 13:16:48,399 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 76f5874bdc2210da6be360b9991ed804689b1623a0180577df5607e0ad5d02da [2021-12-21 13:16:48,622 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-21 13:16:48,651 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-21 13:16:48,653 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-21 13:16:48,654 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-21 13:16:48,654 INFO L275 PluginConnector]: CDTParser initialized [2021-12-21 13:16:48,655 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c [2021-12-21 13:16:48,694 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/09b0fd7fa/f239b62ed667493ca11ebb7af903fea4/FLAG3efdd55bd [2021-12-21 13:16:49,051 INFO L306 CDTParser]: Found 1 translation units. [2021-12-21 13:16:49,051 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c [2021-12-21 13:16:49,063 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/09b0fd7fa/f239b62ed667493ca11ebb7af903fea4/FLAG3efdd55bd [2021-12-21 13:16:49,421 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/09b0fd7fa/f239b62ed667493ca11ebb7af903fea4 [2021-12-21 13:16:49,423 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-21 13:16:49,424 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-21 13:16:49,425 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-21 13:16:49,425 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-21 13:16:49,427 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-21 13:16:49,428 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,429 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@57f0b712 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49, skipping insertion in model container [2021-12-21 13:16:49,429 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,433 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-21 13:16:49,453 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-21 13:16:49,640 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c[3693,3706] [2021-12-21 13:16:49,686 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:16:49,692 INFO L203 MainTranslator]: Completed pre-run [2021-12-21 13:16:49,707 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product42.cil.c[3693,3706] [2021-12-21 13:16:49,762 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-21 13:16:49,774 INFO L208 MainTranslator]: Completed translation [2021-12-21 13:16:49,775 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49 WrapperNode [2021-12-21 13:16:49,776 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-21 13:16:49,777 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-21 13:16:49,777 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-21 13:16:49,777 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-21 13:16:49,781 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,799 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,831 INFO L137 Inliner]: procedures = 56, calls = 155, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 254 [2021-12-21 13:16:49,831 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-21 13:16:49,832 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-21 13:16:49,832 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-21 13:16:49,832 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-21 13:16:49,838 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,838 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,847 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,854 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,857 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,864 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,865 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,875 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-21 13:16:49,875 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-21 13:16:49,875 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-21 13:16:49,875 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-21 13:16:49,876 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (1/1) ... [2021-12-21 13:16:49,880 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-21 13:16:49,890 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:16:49,913 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-21 13:16:49,918 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-21 13:16:49,937 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-21 13:16:49,938 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-21 13:16:49,938 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-21 13:16:49,938 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-21 13:16:49,938 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-21 13:16:49,938 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-21 13:16:49,938 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-21 13:16:49,938 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-21 13:16:49,939 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-21 13:16:49,939 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2021-12-21 13:16:49,939 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2021-12-21 13:16:49,939 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-21 13:16:49,939 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-21 13:16:49,939 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-21 13:16:49,939 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-21 13:16:49,939 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-21 13:16:49,993 INFO L234 CfgBuilder]: Building ICFG [2021-12-21 13:16:49,994 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-21 13:16:50,187 INFO L275 CfgBuilder]: Performing block encoding [2021-12-21 13:16:50,192 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-21 13:16:50,192 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-21 13:16:50,193 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:16:50 BoogieIcfgContainer [2021-12-21 13:16:50,193 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-21 13:16:50,195 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-21 13:16:50,195 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-21 13:16:50,197 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-21 13:16:50,198 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.12 01:16:49" (1/3) ... [2021-12-21 13:16:50,198 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@4900c488 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:16:50, skipping insertion in model container [2021-12-21 13:16:50,198 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.12 01:16:49" (2/3) ... [2021-12-21 13:16:50,199 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@4900c488 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.12 01:16:50, skipping insertion in model container [2021-12-21 13:16:50,199 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:16:50" (3/3) ... [2021-12-21 13:16:50,200 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product42.cil.c [2021-12-21 13:16:50,203 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-21 13:16:50,203 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-21 13:16:50,240 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-21 13:16:50,245 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-21 13:16:50,246 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-21 13:16:50,261 INFO L276 IsEmpty]: Start isEmpty. Operand has 85 states, 67 states have (on average 1.373134328358209) internal successors, (92), 73 states have internal predecessors, (92), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 9 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-21 13:16:50,267 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-21 13:16:50,268 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:50,268 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:50,269 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:50,273 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:50,274 INFO L85 PathProgramCache]: Analyzing trace with hash -690410843, now seen corresponding path program 1 times [2021-12-21 13:16:50,279 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:50,280 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1720968859] [2021-12-21 13:16:50,280 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:50,280 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:50,403 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-21 13:16:50,488 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,505 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-21 13:16:50,506 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,510 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:50,510 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:50,511 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1720968859] [2021-12-21 13:16:50,512 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1720968859] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:50,512 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:50,512 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-21 13:16:50,513 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [447253196] [2021-12-21 13:16:50,514 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:50,517 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-21 13:16:50,517 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:50,537 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-21 13:16:50,538 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:16:50,540 INFO L87 Difference]: Start difference. First operand has 85 states, 67 states have (on average 1.373134328358209) internal successors, (92), 73 states have internal predecessors, (92), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 9 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:16:50,572 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:50,572 INFO L93 Difference]: Finished difference Result 161 states and 218 transitions. [2021-12-21 13:16:50,573 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-21 13:16:50,574 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2021-12-21 13:16:50,574 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:50,580 INFO L225 Difference]: With dead ends: 161 [2021-12-21 13:16:50,580 INFO L226 Difference]: Without dead ends: 76 [2021-12-21 13:16:50,583 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-21 13:16:50,586 INFO L933 BasicCegarLoop]: 106 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 106 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:50,586 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 106 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:50,596 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 76 states. [2021-12-21 13:16:50,615 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 76 to 76. [2021-12-21 13:16:50,616 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 60 states have (on average 1.3) internal successors, (78), 65 states have internal predecessors, (78), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 8 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-21 13:16:50,619 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 97 transitions. [2021-12-21 13:16:50,620 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 97 transitions. Word has length 32 [2021-12-21 13:16:50,620 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:50,620 INFO L470 AbstractCegarLoop]: Abstraction has 76 states and 97 transitions. [2021-12-21 13:16:50,621 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:16:50,621 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 97 transitions. [2021-12-21 13:16:50,623 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2021-12-21 13:16:50,624 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:50,624 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:50,624 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-21 13:16:50,625 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:50,625 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:50,625 INFO L85 PathProgramCache]: Analyzing trace with hash 1965939987, now seen corresponding path program 1 times [2021-12-21 13:16:50,626 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:50,626 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1382933295] [2021-12-21 13:16:50,626 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:50,627 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:50,657 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,698 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-21 13:16:50,702 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,713 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-21 13:16:50,714 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,716 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:50,719 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:50,719 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1382933295] [2021-12-21 13:16:50,719 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1382933295] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:50,719 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:50,719 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:16:50,719 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1773044795] [2021-12-21 13:16:50,720 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:50,720 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:16:50,721 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:50,721 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:16:50,721 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:50,721 INFO L87 Difference]: Start difference. First operand 76 states and 97 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:16:50,733 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:50,734 INFO L93 Difference]: Finished difference Result 116 states and 148 transitions. [2021-12-21 13:16:50,736 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:16:50,736 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2021-12-21 13:16:50,736 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:50,737 INFO L225 Difference]: With dead ends: 116 [2021-12-21 13:16:50,738 INFO L226 Difference]: Without dead ends: 67 [2021-12-21 13:16:50,739 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:50,740 INFO L933 BasicCegarLoop]: 84 mSDtfsCounter, 13 mSDsluCounter, 67 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 151 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:50,742 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 151 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:50,742 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 67 states. [2021-12-21 13:16:50,746 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 67 to 67. [2021-12-21 13:16:50,748 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 67 states, 54 states have (on average 1.3148148148148149) internal successors, (71), 59 states have internal predecessors, (71), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 6 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-21 13:16:50,751 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 67 states to 67 states and 85 transitions. [2021-12-21 13:16:50,752 INFO L78 Accepts]: Start accepts. Automaton has 67 states and 85 transitions. Word has length 33 [2021-12-21 13:16:50,752 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:50,752 INFO L470 AbstractCegarLoop]: Abstraction has 67 states and 85 transitions. [2021-12-21 13:16:50,753 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-21 13:16:50,753 INFO L276 IsEmpty]: Start isEmpty. Operand 67 states and 85 transitions. [2021-12-21 13:16:50,754 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-21 13:16:50,754 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:50,755 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:50,755 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-21 13:16:50,755 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:50,755 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:50,755 INFO L85 PathProgramCache]: Analyzing trace with hash -1695410136, now seen corresponding path program 1 times [2021-12-21 13:16:50,756 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:50,756 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1220074100] [2021-12-21 13:16:50,756 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:50,756 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:50,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,825 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:50,827 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,830 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2021-12-21 13:16:50,831 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,834 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:50,834 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:50,835 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1220074100] [2021-12-21 13:16:50,835 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1220074100] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:50,835 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:50,836 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-21 13:16:50,836 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1607802367] [2021-12-21 13:16:50,836 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:50,837 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-21 13:16:50,837 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:50,838 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-21 13:16:50,839 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-21 13:16:50,839 INFO L87 Difference]: Start difference. First operand 67 states and 85 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:50,907 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:50,910 INFO L93 Difference]: Finished difference Result 126 states and 163 transitions. [2021-12-21 13:16:50,910 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-21 13:16:50,911 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2021-12-21 13:16:50,911 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:50,912 INFO L225 Difference]: With dead ends: 126 [2021-12-21 13:16:50,912 INFO L226 Difference]: Without dead ends: 67 [2021-12-21 13:16:50,913 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-21 13:16:50,914 INFO L933 BasicCegarLoop]: 78 mSDtfsCounter, 108 mSDsluCounter, 122 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 108 SdHoareTripleChecker+Valid, 200 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:50,916 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [108 Valid, 200 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:50,918 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 67 states. [2021-12-21 13:16:50,924 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 67 to 67. [2021-12-21 13:16:50,926 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 67 states, 54 states have (on average 1.2962962962962963) internal successors, (70), 59 states have internal predecessors, (70), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 6 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-21 13:16:50,926 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 67 states to 67 states and 84 transitions. [2021-12-21 13:16:50,927 INFO L78 Accepts]: Start accepts. Automaton has 67 states and 84 transitions. Word has length 38 [2021-12-21 13:16:50,929 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:50,929 INFO L470 AbstractCegarLoop]: Abstraction has 67 states and 84 transitions. [2021-12-21 13:16:50,929 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:50,929 INFO L276 IsEmpty]: Start isEmpty. Operand 67 states and 84 transitions. [2021-12-21 13:16:50,930 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2021-12-21 13:16:50,930 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:50,931 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:50,931 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-21 13:16:50,931 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:50,932 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:50,932 INFO L85 PathProgramCache]: Analyzing trace with hash 610140587, now seen corresponding path program 1 times [2021-12-21 13:16:50,932 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:50,932 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2012041858] [2021-12-21 13:16:50,932 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:50,933 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:50,944 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,962 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:50,963 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,965 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-21 13:16:50,966 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,967 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-21 13:16:50,968 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:50,969 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:50,969 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:50,970 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2012041858] [2021-12-21 13:16:50,970 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2012041858] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:50,970 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:50,970 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:16:50,970 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1485364073] [2021-12-21 13:16:50,970 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:50,971 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:16:50,971 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:50,971 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:16:50,971 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:50,971 INFO L87 Difference]: Start difference. First operand 67 states and 84 transitions. Second operand has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-21 13:16:50,985 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:50,986 INFO L93 Difference]: Finished difference Result 171 states and 219 transitions. [2021-12-21 13:16:50,986 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:16:50,986 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 43 [2021-12-21 13:16:50,986 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:50,987 INFO L225 Difference]: With dead ends: 171 [2021-12-21 13:16:50,987 INFO L226 Difference]: Without dead ends: 112 [2021-12-21 13:16:50,988 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:50,988 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 52 mSDsluCounter, 57 mSDsCounter, 0 mSdLazyCounter, 7 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 52 SdHoareTripleChecker+Valid, 150 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 7 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:50,989 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [52 Valid, 150 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 7 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:50,989 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 112 states. [2021-12-21 13:16:50,996 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 112 to 110. [2021-12-21 13:16:50,996 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 110 states, 87 states have (on average 1.2873563218390804) internal successors, (112), 94 states have internal predecessors, (112), 12 states have call successors, (12), 10 states have call predecessors, (12), 10 states have return successors, (14), 12 states have call predecessors, (14), 12 states have call successors, (14) [2021-12-21 13:16:50,997 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 110 states to 110 states and 138 transitions. [2021-12-21 13:16:50,997 INFO L78 Accepts]: Start accepts. Automaton has 110 states and 138 transitions. Word has length 43 [2021-12-21 13:16:50,997 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:50,998 INFO L470 AbstractCegarLoop]: Abstraction has 110 states and 138 transitions. [2021-12-21 13:16:50,998 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-21 13:16:50,998 INFO L276 IsEmpty]: Start isEmpty. Operand 110 states and 138 transitions. [2021-12-21 13:16:50,999 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2021-12-21 13:16:50,999 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:50,999 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:50,999 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-21 13:16:51,000 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,000 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,000 INFO L85 PathProgramCache]: Analyzing trace with hash 1028234707, now seen corresponding path program 1 times [2021-12-21 13:16:51,000 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,001 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1860458473] [2021-12-21 13:16:51,001 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,001 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,023 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,062 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:51,064 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,068 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2021-12-21 13:16:51,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,071 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-21 13:16:51,072 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,079 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-21 13:16:51,079 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,079 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1860458473] [2021-12-21 13:16:51,080 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1860458473] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:51,080 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:51,080 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-21 13:16:51,080 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1142130387] [2021-12-21 13:16:51,080 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:51,081 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-21 13:16:51,081 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:51,081 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-21 13:16:51,081 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-21 13:16:51,082 INFO L87 Difference]: Start difference. First operand 110 states and 138 transitions. Second operand has 6 states, 6 states have (on average 7.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-21 13:16:51,159 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:51,159 INFO L93 Difference]: Finished difference Result 217 states and 276 transitions. [2021-12-21 13:16:51,160 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-21 13:16:51,160 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 49 [2021-12-21 13:16:51,161 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:51,163 INFO L225 Difference]: With dead ends: 217 [2021-12-21 13:16:51,163 INFO L226 Difference]: Without dead ends: 115 [2021-12-21 13:16:51,165 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-21 13:16:51,168 INFO L933 BasicCegarLoop]: 95 mSDtfsCounter, 36 mSDsluCounter, 310 mSDsCounter, 0 mSdLazyCounter, 50 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 37 SdHoareTripleChecker+Valid, 405 SdHoareTripleChecker+Invalid, 54 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 50 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:51,169 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [37 Valid, 405 Invalid, 54 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 50 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:51,170 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 115 states. [2021-12-21 13:16:51,179 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 115 to 109. [2021-12-21 13:16:51,179 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 109 states, 86 states have (on average 1.2674418604651163) internal successors, (109), 93 states have internal predecessors, (109), 12 states have call successors, (12), 10 states have call predecessors, (12), 10 states have return successors, (14), 12 states have call predecessors, (14), 12 states have call successors, (14) [2021-12-21 13:16:51,180 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 109 states to 109 states and 135 transitions. [2021-12-21 13:16:51,180 INFO L78 Accepts]: Start accepts. Automaton has 109 states and 135 transitions. Word has length 49 [2021-12-21 13:16:51,180 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:51,180 INFO L470 AbstractCegarLoop]: Abstraction has 109 states and 135 transitions. [2021-12-21 13:16:51,180 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-21 13:16:51,180 INFO L276 IsEmpty]: Start isEmpty. Operand 109 states and 135 transitions. [2021-12-21 13:16:51,181 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-21 13:16:51,181 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:51,181 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:51,182 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-21 13:16:51,182 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,182 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,182 INFO L85 PathProgramCache]: Analyzing trace with hash -2048289411, now seen corresponding path program 1 times [2021-12-21 13:16:51,182 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,183 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2090998800] [2021-12-21 13:16:51,183 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,183 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,194 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,214 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:51,214 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,216 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-21 13:16:51,216 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,218 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:51,218 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,218 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2090998800] [2021-12-21 13:16:51,218 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2090998800] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:51,219 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:51,219 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-21 13:16:51,219 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [762681838] [2021-12-21 13:16:51,219 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:51,219 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-21 13:16:51,219 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:51,220 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-21 13:16:51,220 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-21 13:16:51,220 INFO L87 Difference]: Start difference. First operand 109 states and 135 transitions. Second operand has 5 states, 5 states have (on average 8.8) internal successors, (44), 5 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,245 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:51,245 INFO L93 Difference]: Finished difference Result 234 states and 298 transitions. [2021-12-21 13:16:51,245 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-21 13:16:51,246 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.8) internal successors, (44), 5 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 51 [2021-12-21 13:16:51,246 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:51,247 INFO L225 Difference]: With dead ends: 234 [2021-12-21 13:16:51,247 INFO L226 Difference]: Without dead ends: 133 [2021-12-21 13:16:51,247 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-21 13:16:51,248 INFO L933 BasicCegarLoop]: 97 mSDtfsCounter, 33 mSDsluCounter, 251 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 348 SdHoareTripleChecker+Invalid, 20 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:51,248 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [35 Valid, 348 Invalid, 20 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:51,249 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 133 states. [2021-12-21 13:16:51,255 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 133 to 112. [2021-12-21 13:16:51,255 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 112 states, 89 states have (on average 1.2584269662921348) internal successors, (112), 96 states have internal predecessors, (112), 12 states have call successors, (12), 10 states have call predecessors, (12), 10 states have return successors, (14), 12 states have call predecessors, (14), 12 states have call successors, (14) [2021-12-21 13:16:51,256 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 112 states to 112 states and 138 transitions. [2021-12-21 13:16:51,256 INFO L78 Accepts]: Start accepts. Automaton has 112 states and 138 transitions. Word has length 51 [2021-12-21 13:16:51,256 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:51,257 INFO L470 AbstractCegarLoop]: Abstraction has 112 states and 138 transitions. [2021-12-21 13:16:51,257 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.8) internal successors, (44), 5 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,257 INFO L276 IsEmpty]: Start isEmpty. Operand 112 states and 138 transitions. [2021-12-21 13:16:51,258 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-21 13:16:51,258 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:51,258 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:51,258 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-21 13:16:51,258 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,258 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,259 INFO L85 PathProgramCache]: Analyzing trace with hash -1625587585, now seen corresponding path program 1 times [2021-12-21 13:16:51,259 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,259 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1732432627] [2021-12-21 13:16:51,259 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,259 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,269 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,286 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:51,287 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,289 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-21 13:16:51,289 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,291 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:51,291 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,291 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1732432627] [2021-12-21 13:16:51,291 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1732432627] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:51,291 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:51,292 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-12-21 13:16:51,292 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1041252292] [2021-12-21 13:16:51,292 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:51,292 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2021-12-21 13:16:51,292 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:51,293 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2021-12-21 13:16:51,293 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-12-21 13:16:51,293 INFO L87 Difference]: Start difference. First operand 112 states and 138 transitions. Second operand has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,310 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:51,310 INFO L93 Difference]: Finished difference Result 232 states and 293 transitions. [2021-12-21 13:16:51,310 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2021-12-21 13:16:51,310 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 51 [2021-12-21 13:16:51,311 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:51,311 INFO L225 Difference]: With dead ends: 232 [2021-12-21 13:16:51,312 INFO L226 Difference]: Without dead ends: 128 [2021-12-21 13:16:51,312 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2021-12-21 13:16:51,313 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 27 mSDsluCounter, 160 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 27 SdHoareTripleChecker+Valid, 246 SdHoareTripleChecker+Invalid, 13 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:51,313 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [27 Valid, 246 Invalid, 13 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:51,313 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 128 states. [2021-12-21 13:16:51,319 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 128 to 114. [2021-12-21 13:16:51,319 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 114 states, 91 states have (on average 1.2527472527472527) internal successors, (114), 98 states have internal predecessors, (114), 12 states have call successors, (12), 10 states have call predecessors, (12), 10 states have return successors, (14), 12 states have call predecessors, (14), 12 states have call successors, (14) [2021-12-21 13:16:51,320 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 114 states to 114 states and 140 transitions. [2021-12-21 13:16:51,320 INFO L78 Accepts]: Start accepts. Automaton has 114 states and 140 transitions. Word has length 51 [2021-12-21 13:16:51,320 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:51,321 INFO L470 AbstractCegarLoop]: Abstraction has 114 states and 140 transitions. [2021-12-21 13:16:51,321 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,321 INFO L276 IsEmpty]: Start isEmpty. Operand 114 states and 140 transitions. [2021-12-21 13:16:51,321 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-21 13:16:51,321 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:51,322 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:51,322 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-21 13:16:51,322 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,322 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,323 INFO L85 PathProgramCache]: Analyzing trace with hash 863941377, now seen corresponding path program 1 times [2021-12-21 13:16:51,323 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,323 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [958863299] [2021-12-21 13:16:51,323 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,323 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,332 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,355 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-21 13:16:51,356 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-21 13:16:51,358 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,360 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:51,360 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,360 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [958863299] [2021-12-21 13:16:51,360 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [958863299] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:51,360 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:51,360 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-21 13:16:51,360 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1953236487] [2021-12-21 13:16:51,361 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:51,361 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-21 13:16:51,361 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:51,361 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-21 13:16:51,361 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:51,362 INFO L87 Difference]: Start difference. First operand 114 states and 140 transitions. Second operand has 3 states, 3 states have (on average 14.666666666666666) internal successors, (44), 3 states have internal predecessors, (44), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,375 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:51,375 INFO L93 Difference]: Finished difference Result 266 states and 331 transitions. [2021-12-21 13:16:51,375 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-21 13:16:51,376 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 14.666666666666666) internal successors, (44), 3 states have internal predecessors, (44), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 51 [2021-12-21 13:16:51,376 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:51,377 INFO L225 Difference]: With dead ends: 266 [2021-12-21 13:16:51,377 INFO L226 Difference]: Without dead ends: 160 [2021-12-21 13:16:51,377 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-21 13:16:51,378 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 35 mSDsluCounter, 70 mSDsCounter, 0 mSdLazyCounter, 10 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 159 SdHoareTripleChecker+Invalid, 11 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 10 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:51,378 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [35 Valid, 159 Invalid, 11 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 10 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-21 13:16:51,378 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 160 states. [2021-12-21 13:16:51,385 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 160 to 160. [2021-12-21 13:16:51,385 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 160 states, 127 states have (on average 1.2283464566929134) internal successors, (156), 135 states have internal predecessors, (156), 18 states have call successors, (18), 15 states have call predecessors, (18), 14 states have return successors, (20), 17 states have call predecessors, (20), 18 states have call successors, (20) [2021-12-21 13:16:51,386 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 160 states to 160 states and 194 transitions. [2021-12-21 13:16:51,386 INFO L78 Accepts]: Start accepts. Automaton has 160 states and 194 transitions. Word has length 51 [2021-12-21 13:16:51,386 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:51,386 INFO L470 AbstractCegarLoop]: Abstraction has 160 states and 194 transitions. [2021-12-21 13:16:51,386 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 14.666666666666666) internal successors, (44), 3 states have internal predecessors, (44), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-21 13:16:51,386 INFO L276 IsEmpty]: Start isEmpty. Operand 160 states and 194 transitions. [2021-12-21 13:16:51,387 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2021-12-21 13:16:51,387 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:51,387 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:51,387 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-21 13:16:51,387 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,388 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,388 INFO L85 PathProgramCache]: Analyzing trace with hash 159207591, now seen corresponding path program 1 times [2021-12-21 13:16:51,388 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,388 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [768867602] [2021-12-21 13:16:51,388 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,388 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,416 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,463 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-21 13:16:51,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,478 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-21 13:16:51,478 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 47 [2021-12-21 13:16:51,481 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,482 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-21 13:16:51,483 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,483 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [768867602] [2021-12-21 13:16:51,483 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [768867602] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-21 13:16:51,483 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-21 13:16:51,483 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-21 13:16:51,483 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [11404892] [2021-12-21 13:16:51,483 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-21 13:16:51,483 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-21 13:16:51,484 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:51,484 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-21 13:16:51,484 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2021-12-21 13:16:51,484 INFO L87 Difference]: Start difference. First operand 160 states and 194 transitions. Second operand has 8 states, 8 states have (on average 5.75) internal successors, (46), 7 states have internal predecessors, (46), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-21 13:16:51,703 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:51,704 INFO L93 Difference]: Finished difference Result 540 states and 679 transitions. [2021-12-21 13:16:51,704 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-21 13:16:51,704 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.75) internal successors, (46), 7 states have internal predecessors, (46), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 55 [2021-12-21 13:16:51,705 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:51,706 INFO L225 Difference]: With dead ends: 540 [2021-12-21 13:16:51,706 INFO L226 Difference]: Without dead ends: 434 [2021-12-21 13:16:51,707 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 7 SyntacticMatches, 1 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 24 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=56, Invalid=184, Unknown=0, NotChecked=0, Total=240 [2021-12-21 13:16:51,708 INFO L933 BasicCegarLoop]: 128 mSDtfsCounter, 223 mSDsluCounter, 517 mSDsCounter, 0 mSdLazyCounter, 279 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 232 SdHoareTripleChecker+Valid, 645 SdHoareTripleChecker+Invalid, 329 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 279 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:51,708 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [232 Valid, 645 Invalid, 329 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 279 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-21 13:16:51,708 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 434 states. [2021-12-21 13:16:51,727 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 434 to 400. [2021-12-21 13:16:51,727 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 400 states, 319 states have (on average 1.2163009404388714) internal successors, (388), 341 states have internal predecessors, (388), 44 states have call successors, (44), 33 states have call predecessors, (44), 36 states have return successors, (54), 42 states have call predecessors, (54), 44 states have call successors, (54) [2021-12-21 13:16:51,729 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 400 states to 400 states and 486 transitions. [2021-12-21 13:16:51,729 INFO L78 Accepts]: Start accepts. Automaton has 400 states and 486 transitions. Word has length 55 [2021-12-21 13:16:51,729 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:51,729 INFO L470 AbstractCegarLoop]: Abstraction has 400 states and 486 transitions. [2021-12-21 13:16:51,729 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.75) internal successors, (46), 7 states have internal predecessors, (46), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-21 13:16:51,730 INFO L276 IsEmpty]: Start isEmpty. Operand 400 states and 486 transitions. [2021-12-21 13:16:51,730 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 88 [2021-12-21 13:16:51,730 INFO L506 BasicCegarLoop]: Found error trace [2021-12-21 13:16:51,731 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:51,731 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-21 13:16:51,731 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-21 13:16:51,731 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-21 13:16:51,731 INFO L85 PathProgramCache]: Analyzing trace with hash -2045084638, now seen corresponding path program 1 times [2021-12-21 13:16:51,731 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-21 13:16:51,732 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1648987518] [2021-12-21 13:16:51,732 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,732 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-21 13:16:51,742 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-21 13:16:51,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,793 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-21 13:16:51,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,806 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-21 13:16:51,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2021-12-21 13:16:51,809 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,816 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 72 [2021-12-21 13:16:51,816 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,818 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2021-12-21 13:16:51,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,820 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 18 proven. 7 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-21 13:16:51,820 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-21 13:16:51,820 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1648987518] [2021-12-21 13:16:51,820 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1648987518] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-21 13:16:51,820 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [874643575] [2021-12-21 13:16:51,820 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-21 13:16:51,821 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-21 13:16:51,821 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-21 13:16:51,822 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-21 13:16:51,823 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-21 13:16:51,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-21 13:16:51,919 INFO L263 TraceCheckSpWp]: Trace formula consists of 454 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-21 13:16:51,925 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-21 13:16:52,118 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 23 proven. 7 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-21 13:16:52,119 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-21 13:16:52,318 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 19 proven. 6 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-21 13:16:52,318 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [874643575] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-21 13:16:52,318 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-21 13:16:52,318 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 15 [2021-12-21 13:16:52,319 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1407868777] [2021-12-21 13:16:52,319 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-21 13:16:52,319 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2021-12-21 13:16:52,319 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-21 13:16:52,319 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2021-12-21 13:16:52,319 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=35, Invalid=175, Unknown=0, NotChecked=0, Total=210 [2021-12-21 13:16:52,320 INFO L87 Difference]: Start difference. First operand 400 states and 486 transitions. Second operand has 15 states, 15 states have (on average 7.2) internal successors, (108), 11 states have internal predecessors, (108), 5 states have call successors, (16), 6 states have call predecessors, (16), 6 states have return successors, (13), 7 states have call predecessors, (13), 5 states have call successors, (13) [2021-12-21 13:16:52,729 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-21 13:16:52,729 INFO L93 Difference]: Finished difference Result 638 states and 800 transitions. [2021-12-21 13:16:52,730 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2021-12-21 13:16:52,730 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 15 states have (on average 7.2) internal successors, (108), 11 states have internal predecessors, (108), 5 states have call successors, (16), 6 states have call predecessors, (16), 6 states have return successors, (13), 7 states have call predecessors, (13), 5 states have call successors, (13) Word has length 87 [2021-12-21 13:16:52,730 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-21 13:16:52,730 INFO L225 Difference]: With dead ends: 638 [2021-12-21 13:16:52,730 INFO L226 Difference]: Without dead ends: 0 [2021-12-21 13:16:52,732 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 219 GetRequests, 189 SyntacticMatches, 1 SemanticMatches, 29 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 154 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=176, Invalid=754, Unknown=0, NotChecked=0, Total=930 [2021-12-21 13:16:52,732 INFO L933 BasicCegarLoop]: 153 mSDtfsCounter, 282 mSDsluCounter, 822 mSDsCounter, 0 mSdLazyCounter, 544 mSolverCounterSat, 113 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 283 SdHoareTripleChecker+Valid, 975 SdHoareTripleChecker+Invalid, 657 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 113 IncrementalHoareTripleChecker+Valid, 544 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-21 13:16:52,732 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [283 Valid, 975 Invalid, 657 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [113 Valid, 544 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-21 13:16:52,733 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-21 13:16:52,733 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-21 13:16:52,733 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-21 13:16:52,733 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-21 13:16:52,733 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 87 [2021-12-21 13:16:52,733 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-21 13:16:52,733 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-21 13:16:52,733 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 15 states, 15 states have (on average 7.2) internal successors, (108), 11 states have internal predecessors, (108), 5 states have call successors, (16), 6 states have call predecessors, (16), 6 states have return successors, (13), 7 states have call predecessors, (13), 5 states have call successors, (13) [2021-12-21 13:16:52,733 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-21 13:16:52,733 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-21 13:16:52,735 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-21 13:16:52,765 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-21 13:16:52,936 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-21 13:16:52,938 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-21 13:16:54,907 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 815 821) no Hoare annotation was computed. [2021-12-21 13:16:54,907 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 815 821) the Hoare annotation is: true [2021-12-21 13:16:54,908 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 647 658) the Hoare annotation is: true [2021-12-21 13:16:54,908 INFO L858 garLoopResultBuilder]: For program point L651-1(lines 647 658) no Hoare annotation was computed. [2021-12-21 13:16:54,908 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 647 658) no Hoare annotation was computed. [2021-12-21 13:16:54,909 INFO L858 garLoopResultBuilder]: For program point L704(lines 704 710) no Hoare annotation was computed. [2021-12-21 13:16:54,909 INFO L858 garLoopResultBuilder]: For program point L795(lines 795 801) no Hoare annotation was computed. [2021-12-21 13:16:54,909 INFO L858 garLoopResultBuilder]: For program point L795-2(lines 791 813) no Hoare annotation was computed. [2021-12-21 13:16:54,909 INFO L854 garLoopResultBuilder]: At program point L696(lines 691 699) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= ~waterLevel~0 1)) (.cse8 (= ~pumpRunning~0 0)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (< 1 |old(~waterLevel~0)|))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse3 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse4 .cse3 .cse5 (and .cse1 .cse6 .cse2)) (or .cse7 (not (= |old(~waterLevel~0)| 1)) (and .cse8 .cse6) .cse3) (let ((.cse9 (= 2 |timeShift_getWaterLevel_#res#1|)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse8 .cse9 .cse10) .cse7 .cse4 (and .cse1 .cse9 .cse10) .cse3 .cse5)))) [2021-12-21 13:16:54,909 INFO L854 garLoopResultBuilder]: At program point L853(lines 848 855) the Hoare annotation is: (let ((.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (and (<= 1 ~pumpRunning~0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (or .cse4 .cse1 .cse2 .cse3) (or .cse4 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2021-12-21 13:16:54,909 INFO L858 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2021-12-21 13:16:54,909 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 788 814) no Hoare annotation was computed. [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L69(lines 62 71) the Hoare annotation is: (let ((.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse6 (not (< 1 |old(~waterLevel~0)|))) (.cse1 (and (<= 1 ~pumpRunning~0) .cse5 (<= 1 ~switchedOnBeforeTS~0))) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse3 (and .cse4 .cse5) .cse6 .cse2 .cse7) (or .cse0 .cse6 .cse1 .cse2 .cse7) (or .cse3 (not (= |old(~waterLevel~0)| 1)) (and .cse4 (= ~waterLevel~0 1)) .cse2)))) [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L709(lines 700 713) the Hoare annotation is: (let ((.cse3 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (not (< 1 |old(~waterLevel~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift_isHighWaterSensorDry_#res#1| 1) .cse1 (= ~waterLevel~0 1)) .cse2) (or .cse3 .cse4 .cse2 .cse5) (or .cse3 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4 .cse2 .cse5))) [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L837(line 837) the Hoare annotation is: (let ((.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0)) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (= |timeShift_processEnvironment_~tmp~6#1| 0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 (and .cse5 .cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 .cse2 .cse3) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2 (and .cse5 .cse6 (= ~waterLevel~0 1))))) [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L953(lines 938 956) the Hoare annotation is: (let ((.cse3 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (not (< 1 |old(~waterLevel~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse1 (= |timeShift_isHighWaterLevel_~tmp___0~2#1| 0) (= |timeShift_isHighWaterLevel_#res#1| 0) (= ~waterLevel~0 1)) .cse2) (or .cse3 .cse4 .cse2 .cse5) (or .cse3 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4 .cse2 .cse5))) [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L664(lines 659 667) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 .cse2 .cse3) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2021-12-21 13:16:54,911 INFO L858 garLoopResultBuilder]: For program point L627(lines 627 631) no Hoare annotation was computed. [2021-12-21 13:16:54,911 INFO L854 garLoopResultBuilder]: At program point L82(line 82) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse5 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (= ~waterLevel~0 1)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse5 .cse3 .cse6) (or .cse0 .cse5 .cse3 .cse6 (and .cse1 .cse7 .cse2)) (or .cse4 (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) .cse7) .cse3))) [2021-12-21 13:16:54,912 INFO L854 garLoopResultBuilder]: At program point L627-2(lines 623 634) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse5 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse5 .cse3 .cse6) (or .cse0 .cse5 .cse3 .cse6 (and .cse1 (= ~waterLevel~0 1) .cse2)) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse3))) [2021-12-21 13:16:54,912 INFO L858 garLoopResultBuilder]: For program point L82-1(line 82) no Hoare annotation was computed. [2021-12-21 13:16:54,913 INFO L854 garLoopResultBuilder]: At program point L842(line 842) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse5 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse5 .cse3 .cse6) (or .cse0 .cse5 .cse3 .cse6 (and .cse1 (= ~waterLevel~0 1) .cse2)) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse3))) [2021-12-21 13:16:54,913 INFO L854 garLoopResultBuilder]: At program point L842-1(lines 823 847) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse7 (not (< 1 |old(~waterLevel~0)|))) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse9 (= ~waterLevel~0 1)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (let ((.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse4 (and .cse5 .cse6) .cse7 (and .cse1 .cse6) .cse3 .cse8)) (or .cse0 .cse7 .cse3 .cse8 (and .cse1 .cse9 .cse2)) (or .cse4 (not (= |old(~waterLevel~0)| 1)) (and .cse5 .cse9) .cse3))) [2021-12-21 13:16:54,913 INFO L858 garLoopResultBuilder]: For program point L211(line 211) no Hoare annotation was computed. [2021-12-21 13:16:54,913 INFO L854 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: (let ((.cse1 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (= 0 ~systemActive~0)) (.cse7 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse8))) (and (or (and .cse0 .cse1 (= ~waterLevel~0 1)) .cse2 (not (= |old(~waterLevel~0)| 1)) .cse3) (or .cse4 .cse5 .cse3 .cse6 .cse7) (or (and .cse0 .cse1 .cse8) .cse2 .cse5 .cse3 .cse6) (or .cse4 .cse3 .cse7 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))))) [2021-12-21 13:16:54,913 INFO L858 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2021-12-21 13:16:54,914 INFO L858 garLoopResultBuilder]: For program point L802-1(lines 802 808) no Hoare annotation was computed. [2021-12-21 13:16:54,914 INFO L858 garLoopResultBuilder]: For program point L864(lines 864 870) no Hoare annotation was computed. [2021-12-21 13:16:54,914 INFO L858 garLoopResultBuilder]: For program point L831(lines 831 839) no Hoare annotation was computed. [2021-12-21 13:16:54,914 INFO L854 garLoopResultBuilder]: At program point L864-2(lines 857 873) the Hoare annotation is: (let ((.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (let ((.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse4 (and (= ~pumpRunning~0 0) .cse5) .cse1 (and (<= 1 ~pumpRunning~0) .cse5) .cse2 .cse3)) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2021-12-21 13:16:54,914 INFO L858 garLoopResultBuilder]: For program point L827(lines 827 844) no Hoare annotation was computed. [2021-12-21 13:16:54,915 INFO L854 garLoopResultBuilder]: At program point L889(lines 882 892) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 .cse2 .cse3) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2021-12-21 13:16:54,915 INFO L858 garLoopResultBuilder]: For program point L84(lines 84 94) no Hoare annotation was computed. [2021-12-21 13:16:54,915 INFO L854 garLoopResultBuilder]: At program point L212(lines 207 214) the Hoare annotation is: (let ((.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 .cse2 .cse3) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2021-12-21 13:16:54,915 INFO L858 garLoopResultBuilder]: For program point L947(lines 947 951) no Hoare annotation was computed. [2021-12-21 13:16:54,915 INFO L858 garLoopResultBuilder]: For program point L947-2(lines 947 951) no Hoare annotation was computed. [2021-12-21 13:16:54,915 INFO L858 garLoopResultBuilder]: For program point L80(lines 80 97) no Hoare annotation was computed. [2021-12-21 13:16:54,915 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 788 814) the Hoare annotation is: (let ((.cse1 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (= 0 ~systemActive~0)) (.cse7 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse8))) (and (or (and .cse0 .cse1 (= ~waterLevel~0 1)) .cse2 (not (= |old(~waterLevel~0)| 1)) .cse3) (or .cse4 .cse5 .cse3 .cse6 .cse7) (or (and .cse0 .cse1 .cse8) .cse2 .cse5 .cse3 .cse6) (or .cse4 .cse3 .cse7 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))))) [2021-12-21 13:16:54,915 INFO L854 garLoopResultBuilder]: At program point L80-1(lines 72 100) the Hoare annotation is: (let ((.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (= ~pumpRunning~0 0)) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (< 1 |old(~waterLevel~0)|))) (.cse1 (<= 1 ~pumpRunning~0)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse4 .cse3 .cse5 (and .cse1 (= ~waterLevel~0 1) .cse2)) (or .cse6 (and .cse7 .cse8) (not (= |old(~waterLevel~0)| 1)) .cse3) (let ((.cse9 (= 2 |timeShift_getWaterLevel_#res#1|)) (.cse10 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2))) (or (and .cse7 .cse9 .cse8 .cse10) .cse6 .cse4 (and .cse1 .cse9 .cse8 .cse10) .cse3 .cse5)))) [2021-12-21 13:16:54,916 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 788 814) no Hoare annotation was computed. [2021-12-21 13:16:54,916 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 211) no Hoare annotation was computed. [2021-12-21 13:16:54,916 INFO L861 garLoopResultBuilder]: At program point L129(lines 104 133) the Hoare annotation is: true [2021-12-21 13:16:54,916 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 104 133) no Hoare annotation was computed. [2021-12-21 13:16:54,916 INFO L858 garLoopResultBuilder]: For program point L125(line 125) no Hoare annotation was computed. [2021-12-21 13:16:54,917 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 104 133) the Hoare annotation is: true [2021-12-21 13:16:54,917 INFO L858 garLoopResultBuilder]: For program point L118(lines 118 122) no Hoare annotation was computed. [2021-12-21 13:16:54,917 INFO L861 garLoopResultBuilder]: At program point L118-1(lines 118 122) the Hoare annotation is: true [2021-12-21 13:16:54,917 INFO L858 garLoopResultBuilder]: For program point L115(line 115) no Hoare annotation was computed. [2021-12-21 13:16:54,917 INFO L861 garLoopResultBuilder]: At program point L114-2(lines 114 128) the Hoare annotation is: true [2021-12-21 13:16:54,917 INFO L861 garLoopResultBuilder]: At program point L110(line 110) the Hoare annotation is: true [2021-12-21 13:16:54,917 INFO L858 garLoopResultBuilder]: For program point L110-1(line 110) no Hoare annotation was computed. [2021-12-21 13:16:54,917 INFO L854 garLoopResultBuilder]: At program point L246(lines 241 249) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2021-12-21 13:16:54,918 INFO L854 garLoopResultBuilder]: At program point L238(lines 234 240) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point L746(lines 746 752) no Hoare annotation was computed. [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point L746-1(lines 746 752) no Hoare annotation was computed. [2021-12-21 13:16:54,918 INFO L854 garLoopResultBuilder]: At program point L771(lines 726 773) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (< 1 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse1 .cse3 .cse5 (= ~waterLevel~0 1) .cse6) (and .cse7 .cse1 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6))) [2021-12-21 13:16:54,918 INFO L854 garLoopResultBuilder]: At program point L738(line 738) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (< 1 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse1 .cse3 .cse5 (= ~waterLevel~0 1) .cse6) (and .cse7 .cse1 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6))) [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point L193(lines 193 200) no Hoare annotation was computed. [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point L193-2(lines 193 200) no Hoare annotation was computed. [2021-12-21 13:16:54,918 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-21 13:16:54,919 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-21 13:16:54,919 INFO L861 garLoopResultBuilder]: At program point L177(lines 169 179) the Hoare annotation is: true [2021-12-21 13:16:54,919 INFO L861 garLoopResultBuilder]: At program point L202(lines 183 205) the Hoare annotation is: true [2021-12-21 13:16:54,919 INFO L854 garLoopResultBuilder]: At program point L231(lines 227 233) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2021-12-21 13:16:54,919 INFO L854 garLoopResultBuilder]: At program point L165(lines 161 167) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~1#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2021-12-21 13:16:54,919 INFO L854 garLoopResultBuilder]: At program point L962(lines 957 964) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (< 1 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse1 .cse3 .cse5 (= ~waterLevel~0 1) .cse6) (and .cse7 .cse1 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6))) [2021-12-21 13:16:54,920 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-21 13:16:54,920 INFO L858 garLoopResultBuilder]: For program point L764(lines 764 768) no Hoare annotation was computed. [2021-12-21 13:16:54,920 INFO L854 garLoopResultBuilder]: At program point L764-2(lines 756 769) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (< 1 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse1 .cse3 .cse5 (= ~waterLevel~0 1) .cse6) (and .cse7 .cse1 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6))) [2021-12-21 13:16:54,920 INFO L858 garLoopResultBuilder]: For program point L727(lines 726 773) no Hoare annotation was computed. [2021-12-21 13:16:54,920 INFO L858 garLoopResultBuilder]: For program point L756(lines 756 769) no Hoare annotation was computed. [2021-12-21 13:16:54,920 INFO L854 garLoopResultBuilder]: At program point L748(line 748) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (< 1 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse1 .cse3 .cse5 (= ~waterLevel~0 1) .cse6) (and .cse7 .cse1 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6))) [2021-12-21 13:16:54,920 INFO L861 garLoopResultBuilder]: At program point L777(lines 716 781) the Hoare annotation is: true [2021-12-21 13:16:54,920 INFO L858 garLoopResultBuilder]: For program point L736(lines 736 742) no Hoare annotation was computed. [2021-12-21 13:16:54,921 INFO L858 garLoopResultBuilder]: For program point L736-1(lines 736 742) no Hoare annotation was computed. [2021-12-21 13:16:54,921 INFO L854 garLoopResultBuilder]: At program point L59(lines 54 61) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~1#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2021-12-21 13:16:54,921 INFO L858 garLoopResultBuilder]: For program point L728(lines 728 732) no Hoare annotation was computed. [2021-12-21 13:16:54,921 INFO L854 garLoopResultBuilder]: At program point L774(lines 725 775) the Hoare annotation is: false [2021-12-21 13:16:54,922 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 635 646) no Hoare annotation was computed. [2021-12-21 13:16:54,922 INFO L858 garLoopResultBuilder]: For program point L639-1(lines 635 646) no Hoare annotation was computed. [2021-12-21 13:16:54,922 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 635 646) the Hoare annotation is: (let ((.cse4 (not (< 1 |old(~waterLevel~0)|))) (.cse0 (not (<= 1 ~pumpRunning~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= ~pumpRunning~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse3 .cse4 .cse1 .cse2 .cse5) (or .cse4 .cse0 .cse1 .cse2 .cse5) (or .cse3 (not (= |old(~waterLevel~0)| 1)) .cse2 (= ~waterLevel~0 1)))) [2021-12-21 13:16:54,922 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 893 901) no Hoare annotation was computed. [2021-12-21 13:16:54,923 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 893 901) the Hoare annotation is: true [2021-12-21 13:16:54,923 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 893 901) no Hoare annotation was computed. [2021-12-21 13:16:54,925 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-21 13:16:54,926 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-21 13:16:54,954 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.12 01:16:54 BoogieIcfgContainer [2021-12-21 13:16:54,958 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-21 13:16:54,959 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-21 13:16:54,959 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-21 13:16:54,959 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-21 13:16:54,960 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.12 01:16:50" (3/4) ... [2021-12-21 13:16:54,962 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-21 13:16:54,965 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-21 13:16:54,965 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-21 13:16:54,966 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-21 13:16:54,966 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-21 13:16:54,966 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-21 13:16:54,966 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2021-12-21 13:16:54,979 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 51 nodes and edges [2021-12-21 13:16:54,979 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-21 13:16:54,979 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-21 13:16:54,980 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-21 13:16:54,980 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-21 13:16:54,980 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:16:54,980 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-21 13:16:54,994 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && \result == 1) && waterLevel == 1) && !(0 == systemActive) [2021-12-21 13:16:54,994 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2021-12-21 13:16:54,994 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2021-12-21 13:16:54,995 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0 && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive))) || (((((1 <= pumpRunning && \result == 1) && splverifierCounter == 0) && tmp == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) [2021-12-21 13:16:54,996 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || ((1 <= pumpRunning && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || ((1 <= pumpRunning && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive) [2021-12-21 13:16:54,996 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:54,996 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0 && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive))) || (((((1 <= pumpRunning && \result == 1) && splverifierCounter == 0) && tmp == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) [2021-12-21 13:16:54,997 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 1)) || 0 == systemActive)) && ((((((((pumpRunning == 0 && 2 == \result) && \old(waterLevel) == waterLevel) && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || (((1 <= pumpRunning && 2 == \result) && \old(waterLevel) == waterLevel) && tmp == 2)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2021-12-21 13:16:54,997 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive) [2021-12-21 13:16:54,997 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && (((((((pumpRunning == 0 && 2 == \result) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || ((1 <= pumpRunning && 2 == \result) && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((\result == 1 && pumpRunning == 0) && waterLevel == 1)) || 0 == systemActive) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (((pumpRunning == 0 && tmp___0 == 0) && \result == 0) && waterLevel == 1)) || 0 == systemActive) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:54,998 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:54,999 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) [2021-12-21 13:16:55,024 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-21 13:16:55,025 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-21 13:16:55,025 INFO L158 Benchmark]: Toolchain (without parser) took 5601.00ms. Allocated memory was 115.3MB in the beginning and 195.0MB in the end (delta: 79.7MB). Free memory was 77.8MB in the beginning and 111.0MB in the end (delta: -33.2MB). Peak memory consumption was 46.4MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,025 INFO L158 Benchmark]: CDTParser took 0.50ms. Allocated memory is still 115.3MB. Free memory is still 94.7MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-21 13:16:55,025 INFO L158 Benchmark]: CACSL2BoogieTranslator took 350.86ms. Allocated memory is still 115.3MB. Free memory was 77.6MB in the beginning and 83.0MB in the end (delta: -5.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,026 INFO L158 Benchmark]: Boogie Procedure Inliner took 54.92ms. Allocated memory is still 115.3MB. Free memory was 83.0MB in the beginning and 80.8MB in the end (delta: 2.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,026 INFO L158 Benchmark]: Boogie Preprocessor took 42.72ms. Allocated memory is still 115.3MB. Free memory was 80.5MB in the beginning and 79.1MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,027 INFO L158 Benchmark]: RCFGBuilder took 318.31ms. Allocated memory is still 115.3MB. Free memory was 79.1MB in the beginning and 62.7MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,027 INFO L158 Benchmark]: TraceAbstraction took 4763.92ms. Allocated memory was 115.3MB in the beginning and 195.0MB in the end (delta: 79.7MB). Free memory was 62.4MB in the beginning and 117.3MB in the end (delta: -55.0MB). Peak memory consumption was 69.7MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,027 INFO L158 Benchmark]: Witness Printer took 65.59ms. Allocated memory is still 195.0MB. Free memory was 117.3MB in the beginning and 111.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-21 13:16:55,029 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.50ms. Allocated memory is still 115.3MB. Free memory is still 94.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 350.86ms. Allocated memory is still 115.3MB. Free memory was 77.6MB in the beginning and 83.0MB in the end (delta: -5.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 54.92ms. Allocated memory is still 115.3MB. Free memory was 83.0MB in the beginning and 80.8MB in the end (delta: 2.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 42.72ms. Allocated memory is still 115.3MB. Free memory was 80.5MB in the beginning and 79.1MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 318.31ms. Allocated memory is still 115.3MB. Free memory was 79.1MB in the beginning and 62.7MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 4763.92ms. Allocated memory was 115.3MB in the beginning and 195.0MB in the end (delta: 79.7MB). Free memory was 62.4MB in the beginning and 117.3MB in the end (delta: -55.0MB). Peak memory consumption was 69.7MB. Max. memory is 16.1GB. * Witness Printer took 65.59ms. Allocated memory is still 195.0MB. Free memory was 117.3MB in the beginning and 111.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 211]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 85 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 4.7s, OverallIterations: 10, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.0s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 825 SdHoareTripleChecker+Valid, 0.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 809 mSDsluCounter, 3385 SdHoareTripleChecker+Invalid, 0.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2376 mSDsCounter, 191 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 922 IncrementalHoareTripleChecker+Invalid, 1113 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 191 mSolverCounterUnsat, 1009 mSDtfsCounter, 922 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 318 GetRequests, 249 SyntacticMatches, 3 SemanticMatches, 66 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 181 ImplicationChecksByTransitivity, 0.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=400occurred in iteration=9, InterpolantAutomatonStates: 70, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 10 MinimizatonAttempts, 77 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 40 LocationsWithAnnotation, 685 PreInvPairs, 798 NumberOfFragments, 1951 HoareAnnotationTreeSize, 685 FomulaSimplifications, 501 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 40 FomulaSimplificationsInter, 3232 FormulaSimplificationTreeSizeReductionInter, 1.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 0.9s InterpolantComputationTime, 577 NumberOfCodeBlocks, 577 NumberOfCodeBlocksAsserted, 11 NumberOfCheckSat, 652 ConstructedInterpolants, 0 QuantifiedInterpolants, 1383 SizeOfPredicates, 3 NumberOfNonLiveVariables, 454 ConjunctsInSsa, 8 ConjunctsInUnsatCore, 12 InterpolantComputations, 9 PerfectInterpolantSequences, 97/117 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 857]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 114]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 823]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive) - InvariantResult [Line: 161]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 227]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 104]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 183]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || ((1 <= pumpRunning && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || ((1 <= pumpRunning && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive) - InvariantResult [Line: 725]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 169]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 659]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 848]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 691]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && (((((((pumpRunning == 0 && 2 == \result) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || ((1 <= pumpRunning && 2 == \result) && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 72]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 1)) || 0 == systemActive)) && ((((((((pumpRunning == 0 && 2 == \result) && \old(waterLevel) == waterLevel) && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || (((1 <= pumpRunning && 2 == \result) && \old(waterLevel) == waterLevel) && tmp == 2)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 716]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 882]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 957]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0 && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive))) || (((((1 <= pumpRunning && \result == 1) && splverifierCounter == 0) && tmp == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) - InvariantResult [Line: 234]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 700]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((\result == 1 && pumpRunning == 0) && waterLevel == 1)) || 0 == systemActive) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 241]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && \result == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 726]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0 && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive))) || (((((1 <= pumpRunning && \result == 1) && splverifierCounter == 0) && tmp == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && \result == 1) && 1 < waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1) && !(0 == systemActive)) - InvariantResult [Line: 623]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || (1 <= pumpRunning && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 207]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || 0 == systemActive) - InvariantResult [Line: 938]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (((pumpRunning == 0 && tmp___0 == 0) && \result == 0) && waterLevel == 1)) || 0 == systemActive) && (((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(1 <= \old(pumpRunning)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 < \old(waterLevel))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) RESULT: Ultimate proved your program to be correct! [2021-12-21 13:16:55,095 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE