./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version aef121e0 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 7bcd24ea8f621c8db79e853f5aaf064ffcae573e6c1e9f03eb1f84bb0c15fc3c --- Real Ultimate output --- This is Ultimate 0.2.1-dev-aef121e [2021-11-23 03:36:00,226 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-11-23 03:36:00,230 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-11-23 03:36:00,298 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-11-23 03:36:00,300 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-11-23 03:36:00,307 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-11-23 03:36:00,310 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-11-23 03:36:00,317 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-11-23 03:36:00,320 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-11-23 03:36:00,329 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-11-23 03:36:00,330 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-11-23 03:36:00,331 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-11-23 03:36:00,332 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-11-23 03:36:00,333 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-11-23 03:36:00,335 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-11-23 03:36:00,337 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-11-23 03:36:00,338 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-11-23 03:36:00,339 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-11-23 03:36:00,350 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-11-23 03:36:00,355 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-11-23 03:36:00,357 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-11-23 03:36:00,364 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-11-23 03:36:00,368 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-11-23 03:36:00,370 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-11-23 03:36:00,379 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-11-23 03:36:00,380 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-11-23 03:36:00,380 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-11-23 03:36:00,383 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-11-23 03:36:00,384 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-11-23 03:36:00,386 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-11-23 03:36:00,386 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-11-23 03:36:00,387 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-11-23 03:36:00,390 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-11-23 03:36:00,391 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-11-23 03:36:00,394 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-11-23 03:36:00,395 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-11-23 03:36:00,396 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-11-23 03:36:00,396 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-11-23 03:36:00,396 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-11-23 03:36:00,398 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-11-23 03:36:00,398 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-11-23 03:36:00,400 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/config/svcomp-Reach-32bit-Taipan_Default.epf [2021-11-23 03:36:00,460 INFO L113 SettingsManager]: Loading preferences was successful [2021-11-23 03:36:00,460 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-11-23 03:36:00,461 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-11-23 03:36:00,461 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-11-23 03:36:00,462 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-11-23 03:36:00,469 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-11-23 03:36:00,470 INFO L138 SettingsManager]: * User list type=DISABLED [2021-11-23 03:36:00,470 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2021-11-23 03:36:00,470 INFO L138 SettingsManager]: * Explicit value domain=true [2021-11-23 03:36:00,470 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2021-11-23 03:36:00,472 INFO L138 SettingsManager]: * Octagon Domain=false [2021-11-23 03:36:00,472 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2021-11-23 03:36:00,472 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2021-11-23 03:36:00,473 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2021-11-23 03:36:00,473 INFO L138 SettingsManager]: * Interval Domain=false [2021-11-23 03:36:00,473 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2021-11-23 03:36:00,473 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2021-11-23 03:36:00,474 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2021-11-23 03:36:00,475 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-11-23 03:36:00,476 INFO L138 SettingsManager]: * sizeof long=4 [2021-11-23 03:36:00,476 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-11-23 03:36:00,476 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-11-23 03:36:00,476 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-11-23 03:36:00,477 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-11-23 03:36:00,477 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-11-23 03:36:00,477 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-11-23 03:36:00,480 INFO L138 SettingsManager]: * sizeof long double=12 [2021-11-23 03:36:00,480 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-11-23 03:36:00,480 INFO L138 SettingsManager]: * Use constant arrays=true [2021-11-23 03:36:00,480 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-11-23 03:36:00,481 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-11-23 03:36:00,481 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-11-23 03:36:00,481 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-11-23 03:36:00,482 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-11-23 03:36:00,482 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-11-23 03:36:00,482 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-11-23 03:36:00,483 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2021-11-23 03:36:00,483 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-11-23 03:36:00,483 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-11-23 03:36:00,483 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-11-23 03:36:00,483 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2021-11-23 03:36:00,484 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 7bcd24ea8f621c8db79e853f5aaf064ffcae573e6c1e9f03eb1f84bb0c15fc3c [2021-11-23 03:36:00,745 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-11-23 03:36:00,783 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-11-23 03:36:00,785 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-11-23 03:36:00,787 INFO L271 PluginConnector]: Initializing CDTParser... [2021-11-23 03:36:00,788 INFO L275 PluginConnector]: CDTParser initialized [2021-11-23 03:36:00,789 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/../../sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c [2021-11-23 03:36:00,892 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/data/a0f699023/a8690710e07545b7b1b0b2b00b4c0966/FLAG62d7c6ec8 [2021-11-23 03:36:01,416 INFO L306 CDTParser]: Found 1 translation units. [2021-11-23 03:36:01,417 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c [2021-11-23 03:36:01,432 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/data/a0f699023/a8690710e07545b7b1b0b2b00b4c0966/FLAG62d7c6ec8 [2021-11-23 03:36:01,720 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/data/a0f699023/a8690710e07545b7b1b0b2b00b4c0966 [2021-11-23 03:36:01,722 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-11-23 03:36:01,724 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-11-23 03:36:01,726 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-11-23 03:36:01,726 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-11-23 03:36:01,730 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-11-23 03:36:01,730 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 03:36:01" (1/1) ... [2021-11-23 03:36:01,732 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@58f16f57 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:01, skipping insertion in model container [2021-11-23 03:36:01,732 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 03:36:01" (1/1) ... [2021-11-23 03:36:01,739 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-11-23 03:36:01,820 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-11-23 03:36:02,090 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c[8146,8159] [2021-11-23 03:36:02,153 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-11-23 03:36:02,162 INFO L203 MainTranslator]: Completed pre-run [2021-11-23 03:36:02,233 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/sv-benchmarks/c/product-lines/minepump_spec5_product56.cil.c[8146,8159] [2021-11-23 03:36:02,291 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-11-23 03:36:02,311 INFO L208 MainTranslator]: Completed translation [2021-11-23 03:36:02,312 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02 WrapperNode [2021-11-23 03:36:02,312 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-11-23 03:36:02,313 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-11-23 03:36:02,313 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-11-23 03:36:02,313 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-11-23 03:36:02,322 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,338 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,372 INFO L137 Inliner]: procedures = 60, calls = 164, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 294 [2021-11-23 03:36:02,376 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-11-23 03:36:02,377 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-11-23 03:36:02,378 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-11-23 03:36:02,378 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-11-23 03:36:02,387 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,388 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,401 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,409 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,416 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,425 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,427 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,430 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-11-23 03:36:02,431 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-11-23 03:36:02,431 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-11-23 03:36:02,432 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-11-23 03:36:02,437 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (1/1) ... [2021-11-23 03:36:02,447 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-11-23 03:36:02,460 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 [2021-11-23 03:36:02,475 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-11-23 03:36:02,496 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-11-23 03:36:02,525 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-11-23 03:36:02,525 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-11-23 03:36:02,525 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-11-23 03:36:02,525 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-11-23 03:36:02,525 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-11-23 03:36:02,525 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-11-23 03:36:02,525 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-11-23 03:36:02,526 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-11-23 03:36:02,526 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2021-11-23 03:36:02,526 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2021-11-23 03:36:02,526 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-11-23 03:36:02,526 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-11-23 03:36:02,526 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-11-23 03:36:02,527 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-11-23 03:36:02,527 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-11-23 03:36:02,527 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-11-23 03:36:02,527 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-11-23 03:36:02,605 INFO L236 CfgBuilder]: Building ICFG [2021-11-23 03:36:02,607 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-11-23 03:36:02,966 INFO L277 CfgBuilder]: Performing block encoding [2021-11-23 03:36:03,138 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-11-23 03:36:03,139 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-11-23 03:36:03,141 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 03:36:03 BoogieIcfgContainer [2021-11-23 03:36:03,142 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-11-23 03:36:03,143 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-11-23 03:36:03,144 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-11-23 03:36:03,147 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-11-23 03:36:03,148 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 23.11 03:36:01" (1/3) ... [2021-11-23 03:36:03,149 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@48a893fb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 03:36:03, skipping insertion in model container [2021-11-23 03:36:03,149 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 03:36:02" (2/3) ... [2021-11-23 03:36:03,149 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@48a893fb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 03:36:03, skipping insertion in model container [2021-11-23 03:36:03,149 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 03:36:03" (3/3) ... [2021-11-23 03:36:03,151 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product56.cil.c [2021-11-23 03:36:03,157 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-11-23 03:36:03,157 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-11-23 03:36:03,231 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-11-23 03:36:03,238 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-11-23 03:36:03,238 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-11-23 03:36:03,257 INFO L276 IsEmpty]: Start isEmpty. Operand has 74 states, 46 states have (on average 1.4565217391304348) internal successors, (67), 57 states have internal predecessors, (67), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2021-11-23 03:36:03,265 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2021-11-23 03:36:03,265 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:03,266 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:03,266 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:03,272 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:03,272 INFO L85 PathProgramCache]: Analyzing trace with hash -1059687252, now seen corresponding path program 1 times [2021-11-23 03:36:03,282 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:03,282 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1804588106] [2021-11-23 03:36:03,282 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:03,283 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:03,398 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:03,469 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-11-23 03:36:03,470 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:03,470 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1804588106] [2021-11-23 03:36:03,471 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1804588106] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:03,471 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:03,471 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-11-23 03:36:03,473 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [644199849] [2021-11-23 03:36:03,474 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:03,478 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-11-23 03:36:03,478 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:03,506 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-11-23 03:36:03,506 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-11-23 03:36:03,509 INFO L87 Difference]: Start difference. First operand has 74 states, 46 states have (on average 1.4565217391304348) internal successors, (67), 57 states have internal predecessors, (67), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:03,582 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:03,582 INFO L93 Difference]: Finished difference Result 146 states and 203 transitions. [2021-11-23 03:36:03,583 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-11-23 03:36:03,585 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2021-11-23 03:36:03,585 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:03,594 INFO L225 Difference]: With dead ends: 146 [2021-11-23 03:36:03,595 INFO L226 Difference]: Without dead ends: 69 [2021-11-23 03:36:03,599 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-11-23 03:36:03,602 INFO L933 BasicCegarLoop]: 79 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 19 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 79 SdHoareTripleChecker+Invalid, 20 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 19 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:03,604 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 79 Invalid, 20 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 19 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-11-23 03:36:03,621 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2021-11-23 03:36:03,644 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2021-11-23 03:36:03,646 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 43 states have (on average 1.372093023255814) internal successors, (59), 53 states have internal predecessors, (59), 17 states have call successors, (17), 9 states have call predecessors, (17), 8 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2021-11-23 03:36:03,648 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 92 transitions. [2021-11-23 03:36:03,650 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 92 transitions. Word has length 21 [2021-11-23 03:36:03,650 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:03,650 INFO L470 AbstractCegarLoop]: Abstraction has 69 states and 92 transitions. [2021-11-23 03:36:03,651 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:03,651 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 92 transitions. [2021-11-23 03:36:03,653 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2021-11-23 03:36:03,654 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:03,654 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:03,654 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-11-23 03:36:03,654 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:03,655 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:03,655 INFO L85 PathProgramCache]: Analyzing trace with hash 1231371985, now seen corresponding path program 1 times [2021-11-23 03:36:03,656 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:03,656 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [803564103] [2021-11-23 03:36:03,656 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:03,656 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:03,683 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:03,724 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-11-23 03:36:03,724 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:03,724 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [803564103] [2021-11-23 03:36:03,724 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [803564103] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:03,725 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:03,725 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-11-23 03:36:03,725 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1679455426] [2021-11-23 03:36:03,725 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:03,726 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-11-23 03:36:03,727 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:03,727 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-11-23 03:36:03,728 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-11-23 03:36:03,728 INFO L87 Difference]: Start difference. First operand 69 states and 92 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:03,777 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:03,777 INFO L93 Difference]: Finished difference Result 110 states and 146 transitions. [2021-11-23 03:36:03,778 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-11-23 03:36:03,778 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2021-11-23 03:36:03,778 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:03,780 INFO L225 Difference]: With dead ends: 110 [2021-11-23 03:36:03,780 INFO L226 Difference]: Without dead ends: 61 [2021-11-23 03:36:03,781 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-11-23 03:36:03,782 INFO L933 BasicCegarLoop]: 65 mSDtfsCounter, 14 mSDsluCounter, 61 mSDsCounter, 0 mSdLazyCounter, 28 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 114 SdHoareTripleChecker+Invalid, 28 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 28 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:03,783 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [18 Valid, 114 Invalid, 28 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 28 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-11-23 03:36:03,784 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2021-11-23 03:36:03,792 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2021-11-23 03:36:03,793 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 38 states have (on average 1.394736842105263) internal successors, (53), 48 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2021-11-23 03:36:03,794 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 81 transitions. [2021-11-23 03:36:03,795 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 81 transitions. Word has length 22 [2021-11-23 03:36:03,795 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:03,795 INFO L470 AbstractCegarLoop]: Abstraction has 61 states and 81 transitions. [2021-11-23 03:36:03,795 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:03,795 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 81 transitions. [2021-11-23 03:36:03,797 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-11-23 03:36:03,797 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:03,797 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:03,797 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-11-23 03:36:03,798 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:03,798 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:03,798 INFO L85 PathProgramCache]: Analyzing trace with hash 88149764, now seen corresponding path program 1 times [2021-11-23 03:36:03,799 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:03,799 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [205080795] [2021-11-23 03:36:03,799 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:03,799 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:03,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:03,864 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-11-23 03:36:03,864 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:03,864 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [205080795] [2021-11-23 03:36:03,864 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [205080795] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:03,865 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:03,865 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-11-23 03:36:03,865 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [638917380] [2021-11-23 03:36:03,865 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:03,866 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-11-23 03:36:03,866 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:03,866 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-11-23 03:36:03,867 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-11-23 03:36:03,867 INFO L87 Difference]: Start difference. First operand 61 states and 81 transitions. Second operand has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-11-23 03:36:03,938 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:03,938 INFO L93 Difference]: Finished difference Result 179 states and 240 transitions. [2021-11-23 03:36:03,939 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-11-23 03:36:03,939 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2021-11-23 03:36:03,939 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:03,942 INFO L225 Difference]: With dead ends: 179 [2021-11-23 03:36:03,942 INFO L226 Difference]: Without dead ends: 120 [2021-11-23 03:36:03,943 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-11-23 03:36:03,944 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 73 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 34 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 73 SdHoareTripleChecker+Valid, 151 SdHoareTripleChecker+Invalid, 35 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 34 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:03,945 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [73 Valid, 151 Invalid, 35 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 34 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-11-23 03:36:03,946 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 120 states. [2021-11-23 03:36:03,965 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 120 to 117. [2021-11-23 03:36:03,966 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 117 states, 72 states have (on average 1.4027777777777777) internal successors, (101), 91 states have internal predecessors, (101), 28 states have call successors, (28), 16 states have call predecessors, (28), 16 states have return successors, (28), 17 states have call predecessors, (28), 28 states have call successors, (28) [2021-11-23 03:36:03,968 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 117 states to 117 states and 157 transitions. [2021-11-23 03:36:03,968 INFO L78 Accepts]: Start accepts. Automaton has 117 states and 157 transitions. Word has length 25 [2021-11-23 03:36:03,969 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:03,969 INFO L470 AbstractCegarLoop]: Abstraction has 117 states and 157 transitions. [2021-11-23 03:36:03,969 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-11-23 03:36:03,969 INFO L276 IsEmpty]: Start isEmpty. Operand 117 states and 157 transitions. [2021-11-23 03:36:03,971 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2021-11-23 03:36:03,971 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:03,972 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:03,972 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-11-23 03:36:03,972 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:03,973 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:03,973 INFO L85 PathProgramCache]: Analyzing trace with hash -577044933, now seen corresponding path program 1 times [2021-11-23 03:36:03,973 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:03,973 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [986570789] [2021-11-23 03:36:03,974 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:03,974 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:03,996 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:04,109 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-11-23 03:36:04,109 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:04,110 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [986570789] [2021-11-23 03:36:04,110 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [986570789] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:04,110 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:04,110 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-11-23 03:36:04,111 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1378444374] [2021-11-23 03:36:04,111 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:04,111 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-11-23 03:36:04,112 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:04,112 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-11-23 03:36:04,112 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-11-23 03:36:04,113 INFO L87 Difference]: Start difference. First operand 117 states and 157 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:04,377 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:04,377 INFO L93 Difference]: Finished difference Result 322 states and 445 transitions. [2021-11-23 03:36:04,377 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-11-23 03:36:04,377 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2021-11-23 03:36:04,378 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:04,387 INFO L225 Difference]: With dead ends: 322 [2021-11-23 03:36:04,387 INFO L226 Difference]: Without dead ends: 207 [2021-11-23 03:36:04,393 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-11-23 03:36:04,399 INFO L933 BasicCegarLoop]: 78 mSDtfsCounter, 41 mSDsluCounter, 296 mSDsCounter, 0 mSdLazyCounter, 135 mSolverCounterSat, 11 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 42 SdHoareTripleChecker+Valid, 331 SdHoareTripleChecker+Invalid, 146 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 11 IncrementalHoareTripleChecker+Valid, 135 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:04,399 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [42 Valid, 331 Invalid, 146 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [11 Valid, 135 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-11-23 03:36:04,401 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 207 states. [2021-11-23 03:36:04,455 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 207 to 198. [2021-11-23 03:36:04,456 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 198 states, 129 states have (on average 1.310077519379845) internal successors, (169), 146 states have internal predecessors, (169), 38 states have call successors, (38), 30 states have call predecessors, (38), 30 states have return successors, (50), 33 states have call predecessors, (50), 38 states have call successors, (50) [2021-11-23 03:36:04,458 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 257 transitions. [2021-11-23 03:36:04,459 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 257 transitions. Word has length 28 [2021-11-23 03:36:04,459 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:04,459 INFO L470 AbstractCegarLoop]: Abstraction has 198 states and 257 transitions. [2021-11-23 03:36:04,460 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2021-11-23 03:36:04,460 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 257 transitions. [2021-11-23 03:36:04,462 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-11-23 03:36:04,462 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:04,462 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:04,462 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-11-23 03:36:04,463 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:04,463 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:04,463 INFO L85 PathProgramCache]: Analyzing trace with hash -1008014715, now seen corresponding path program 1 times [2021-11-23 03:36:04,463 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:04,464 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [414006731] [2021-11-23 03:36:04,464 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:04,464 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:04,497 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:04,599 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-11-23 03:36:04,599 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:04,599 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [414006731] [2021-11-23 03:36:04,600 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [414006731] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:04,601 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:04,602 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-11-23 03:36:04,606 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [368210765] [2021-11-23 03:36:04,608 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:04,609 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-11-23 03:36:04,609 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:04,610 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-11-23 03:36:04,611 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2021-11-23 03:36:04,611 INFO L87 Difference]: Start difference. First operand 198 states and 257 transitions. Second operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2021-11-23 03:36:04,858 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:04,859 INFO L93 Difference]: Finished difference Result 590 states and 762 transitions. [2021-11-23 03:36:04,865 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-11-23 03:36:04,866 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 38 [2021-11-23 03:36:04,867 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:04,876 INFO L225 Difference]: With dead ends: 590 [2021-11-23 03:36:04,876 INFO L226 Difference]: Without dead ends: 394 [2021-11-23 03:36:04,877 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2021-11-23 03:36:04,882 INFO L933 BasicCegarLoop]: 104 mSDtfsCounter, 126 mSDsluCounter, 197 mSDsCounter, 0 mSdLazyCounter, 142 mSolverCounterSat, 24 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 127 SdHoareTripleChecker+Valid, 275 SdHoareTripleChecker+Invalid, 166 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 24 IncrementalHoareTripleChecker+Valid, 142 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:04,883 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [127 Valid, 275 Invalid, 166 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [24 Valid, 142 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-11-23 03:36:04,886 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 394 states. [2021-11-23 03:36:04,950 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 394 to 384. [2021-11-23 03:36:04,952 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 384 states, 251 states have (on average 1.2868525896414342) internal successors, (323), 279 states have internal predecessors, (323), 71 states have call successors, (71), 59 states have call predecessors, (71), 61 states have return successors, (95), 64 states have call predecessors, (95), 71 states have call successors, (95) [2021-11-23 03:36:04,962 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 384 states to 384 states and 489 transitions. [2021-11-23 03:36:04,963 INFO L78 Accepts]: Start accepts. Automaton has 384 states and 489 transitions. Word has length 38 [2021-11-23 03:36:04,963 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:04,963 INFO L470 AbstractCegarLoop]: Abstraction has 384 states and 489 transitions. [2021-11-23 03:36:04,965 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2021-11-23 03:36:04,972 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 489 transitions. [2021-11-23 03:36:04,975 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-11-23 03:36:04,975 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:04,980 INFO L514 BasicCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:04,980 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-11-23 03:36:04,981 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:04,981 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:04,986 INFO L85 PathProgramCache]: Analyzing trace with hash 1238551946, now seen corresponding path program 1 times [2021-11-23 03:36:04,987 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:04,987 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [166113581] [2021-11-23 03:36:04,987 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:04,987 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:05,054 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:05,256 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-11-23 03:36:05,257 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:05,257 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [166113581] [2021-11-23 03:36:05,257 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [166113581] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:05,257 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:05,258 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-11-23 03:36:05,258 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [256682716] [2021-11-23 03:36:05,258 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:05,259 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-11-23 03:36:05,260 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:05,260 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-11-23 03:36:05,262 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2021-11-23 03:36:05,262 INFO L87 Difference]: Start difference. First operand 384 states and 489 transitions. Second operand has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2021-11-23 03:36:05,964 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:05,965 INFO L93 Difference]: Finished difference Result 900 states and 1171 transitions. [2021-11-23 03:36:05,965 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-11-23 03:36:05,966 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) Word has length 41 [2021-11-23 03:36:05,967 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:05,977 INFO L225 Difference]: With dead ends: 900 [2021-11-23 03:36:05,978 INFO L226 Difference]: Without dead ends: 630 [2021-11-23 03:36:05,980 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2021-11-23 03:36:05,983 INFO L933 BasicCegarLoop]: 97 mSDtfsCounter, 232 mSDsluCounter, 279 mSDsCounter, 0 mSdLazyCounter, 422 mSolverCounterSat, 95 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 240 SdHoareTripleChecker+Valid, 335 SdHoareTripleChecker+Invalid, 517 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 95 IncrementalHoareTripleChecker+Valid, 422 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:05,986 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [240 Valid, 335 Invalid, 517 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [95 Valid, 422 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2021-11-23 03:36:05,988 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 630 states. [2021-11-23 03:36:06,092 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 630 to 566. [2021-11-23 03:36:06,098 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 566 states, 376 states have (on average 1.2792553191489362) internal successors, (481), 416 states have internal predecessors, (481), 100 states have call successors, (100), 76 states have call predecessors, (100), 89 states have return successors, (139), 99 states have call predecessors, (139), 100 states have call successors, (139) [2021-11-23 03:36:06,108 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 566 states to 566 states and 720 transitions. [2021-11-23 03:36:06,109 INFO L78 Accepts]: Start accepts. Automaton has 566 states and 720 transitions. Word has length 41 [2021-11-23 03:36:06,111 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:06,112 INFO L470 AbstractCegarLoop]: Abstraction has 566 states and 720 transitions. [2021-11-23 03:36:06,112 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2021-11-23 03:36:06,112 INFO L276 IsEmpty]: Start isEmpty. Operand 566 states and 720 transitions. [2021-11-23 03:36:06,122 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2021-11-23 03:36:06,122 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:06,123 INFO L514 BasicCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:06,125 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-11-23 03:36:06,125 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:06,126 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:06,127 INFO L85 PathProgramCache]: Analyzing trace with hash 800789391, now seen corresponding path program 1 times [2021-11-23 03:36:06,127 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:06,127 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1399938482] [2021-11-23 03:36:06,128 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:06,128 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:06,170 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:06,241 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2021-11-23 03:36:06,242 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:06,242 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1399938482] [2021-11-23 03:36:06,242 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1399938482] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:06,242 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-11-23 03:36:06,243 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-11-23 03:36:06,243 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1743147323] [2021-11-23 03:36:06,243 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:06,244 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2021-11-23 03:36:06,244 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:06,244 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2021-11-23 03:36:06,245 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-11-23 03:36:06,245 INFO L87 Difference]: Start difference. First operand 566 states and 720 transitions. Second operand has 4 states, 3 states have (on average 15.333333333333334) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2021-11-23 03:36:06,393 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:06,393 INFO L93 Difference]: Finished difference Result 943 states and 1198 transitions. [2021-11-23 03:36:06,394 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2021-11-23 03:36:06,394 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 15.333333333333334) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) Word has length 63 [2021-11-23 03:36:06,395 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:06,398 INFO L225 Difference]: With dead ends: 943 [2021-11-23 03:36:06,398 INFO L226 Difference]: Without dead ends: 379 [2021-11-23 03:36:06,400 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-11-23 03:36:06,401 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 104 mSDsluCounter, 71 mSDsCounter, 0 mSdLazyCounter, 92 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 104 SdHoareTripleChecker+Valid, 140 SdHoareTripleChecker+Invalid, 96 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 92 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:06,401 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [104 Valid, 140 Invalid, 96 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 92 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-11-23 03:36:06,402 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 379 states. [2021-11-23 03:36:06,428 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 379 to 373. [2021-11-23 03:36:06,429 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 373 states, 250 states have (on average 1.26) internal successors, (315), 277 states have internal predecessors, (315), 65 states have call successors, (65), 51 states have call predecessors, (65), 57 states have return successors, (84), 64 states have call predecessors, (84), 65 states have call successors, (84) [2021-11-23 03:36:06,432 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 373 states to 373 states and 464 transitions. [2021-11-23 03:36:06,432 INFO L78 Accepts]: Start accepts. Automaton has 373 states and 464 transitions. Word has length 63 [2021-11-23 03:36:06,433 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:06,433 INFO L470 AbstractCegarLoop]: Abstraction has 373 states and 464 transitions. [2021-11-23 03:36:06,433 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 15.333333333333334) internal successors, (46), 4 states have internal predecessors, (46), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2021-11-23 03:36:06,433 INFO L276 IsEmpty]: Start isEmpty. Operand 373 states and 464 transitions. [2021-11-23 03:36:06,435 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 73 [2021-11-23 03:36:06,435 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:06,435 INFO L514 BasicCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:06,435 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-11-23 03:36:06,436 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:06,436 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:06,436 INFO L85 PathProgramCache]: Analyzing trace with hash 1350375381, now seen corresponding path program 1 times [2021-11-23 03:36:06,437 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:06,437 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1923941881] [2021-11-23 03:36:06,437 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:06,437 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:06,455 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:06,513 INFO L134 CoverageAnalysis]: Checked inductivity of 33 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2021-11-23 03:36:06,513 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:06,513 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1923941881] [2021-11-23 03:36:06,514 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1923941881] provided 0 perfect and 1 imperfect interpolant sequences [2021-11-23 03:36:06,514 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [223962085] [2021-11-23 03:36:06,514 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:06,514 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:06,514 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 [2021-11-23 03:36:06,517 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-11-23 03:36:06,525 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-11-23 03:36:06,631 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:06,635 INFO L263 TraceCheckSpWp]: Trace formula consists of 464 conjuncts, 4 conjunts are in the unsatisfiable core [2021-11-23 03:36:06,644 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-11-23 03:36:06,876 INFO L134 CoverageAnalysis]: Checked inductivity of 33 backedges. 33 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-11-23 03:36:06,876 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-11-23 03:36:06,876 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [223962085] provided 1 perfect and 0 imperfect interpolant sequences [2021-11-23 03:36:06,877 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-11-23 03:36:06,877 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [7] total 8 [2021-11-23 03:36:06,877 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1932093995] [2021-11-23 03:36:06,877 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-11-23 03:36:06,878 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-11-23 03:36:06,878 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:06,879 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-11-23 03:36:06,879 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2021-11-23 03:36:06,879 INFO L87 Difference]: Start difference. First operand 373 states and 464 transitions. Second operand has 3 states, 3 states have (on average 17.666666666666668) internal successors, (53), 3 states have internal predecessors, (53), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) [2021-11-23 03:36:06,975 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:06,975 INFO L93 Difference]: Finished difference Result 666 states and 836 transitions. [2021-11-23 03:36:06,976 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-11-23 03:36:06,976 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 17.666666666666668) internal successors, (53), 3 states have internal predecessors, (53), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) Word has length 72 [2021-11-23 03:36:06,977 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:06,982 INFO L225 Difference]: With dead ends: 666 [2021-11-23 03:36:06,982 INFO L226 Difference]: Without dead ends: 363 [2021-11-23 03:36:06,984 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 79 GetRequests, 73 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2021-11-23 03:36:06,985 INFO L933 BasicCegarLoop]: 94 mSDtfsCounter, 40 mSDsluCounter, 53 mSDsCounter, 0 mSdLazyCounter, 42 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 40 SdHoareTripleChecker+Valid, 139 SdHoareTripleChecker+Invalid, 45 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 42 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:06,985 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [40 Valid, 139 Invalid, 45 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 42 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-11-23 03:36:06,987 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 363 states. [2021-11-23 03:36:07,017 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 363 to 363. [2021-11-23 03:36:07,018 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 363 states, 243 states have (on average 1.2263374485596708) internal successors, (298), 268 states have internal predecessors, (298), 63 states have call successors, (63), 51 states have call predecessors, (63), 56 states have return successors, (74), 62 states have call predecessors, (74), 63 states have call successors, (74) [2021-11-23 03:36:07,022 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 363 states to 363 states and 435 transitions. [2021-11-23 03:36:07,022 INFO L78 Accepts]: Start accepts. Automaton has 363 states and 435 transitions. Word has length 72 [2021-11-23 03:36:07,023 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:07,024 INFO L470 AbstractCegarLoop]: Abstraction has 363 states and 435 transitions. [2021-11-23 03:36:07,024 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 17.666666666666668) internal successors, (53), 3 states have internal predecessors, (53), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) [2021-11-23 03:36:07,024 INFO L276 IsEmpty]: Start isEmpty. Operand 363 states and 435 transitions. [2021-11-23 03:36:07,028 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 77 [2021-11-23 03:36:07,028 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:07,029 INFO L514 BasicCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:07,072 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-11-23 03:36:07,243 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:07,243 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:07,243 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:07,244 INFO L85 PathProgramCache]: Analyzing trace with hash -966270148, now seen corresponding path program 1 times [2021-11-23 03:36:07,244 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:07,244 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1770736495] [2021-11-23 03:36:07,244 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:07,244 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:07,263 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:07,347 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 12 proven. 10 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2021-11-23 03:36:07,347 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:07,347 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1770736495] [2021-11-23 03:36:07,348 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1770736495] provided 0 perfect and 1 imperfect interpolant sequences [2021-11-23 03:36:07,348 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [457772579] [2021-11-23 03:36:07,348 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:07,348 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:07,348 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 [2021-11-23 03:36:07,349 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-11-23 03:36:07,367 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-11-23 03:36:07,457 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:07,460 INFO L263 TraceCheckSpWp]: Trace formula consists of 484 conjuncts, 8 conjunts are in the unsatisfiable core [2021-11-23 03:36:07,464 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-11-23 03:36:07,669 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 21 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-11-23 03:36:07,670 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-11-23 03:36:07,908 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 14 proven. 8 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2021-11-23 03:36:07,908 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [457772579] provided 0 perfect and 2 imperfect interpolant sequences [2021-11-23 03:36:07,908 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [816486870] [2021-11-23 03:36:07,940 INFO L159 IcfgInterpreter]: Started Sifa with 49 locations of interest [2021-11-23 03:36:07,940 INFO L166 IcfgInterpreter]: Building call graph [2021-11-23 03:36:07,946 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2021-11-23 03:36:07,953 INFO L176 IcfgInterpreter]: Starting interpretation [2021-11-23 03:36:07,954 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2021-11-23 03:36:16,682 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 50 for LOIs [2021-11-23 03:36:16,694 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 48 for LOIs [2021-11-23 03:36:17,569 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 34 for LOIs [2021-11-23 03:36:17,758 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 69 for LOIs [2021-11-23 03:36:18,123 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 20 for LOIs [2021-11-23 03:36:18,127 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 40 for LOIs [2021-11-23 03:36:18,132 INFO L180 IcfgInterpreter]: Interpretation finished [2021-11-23 03:36:25,055 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '10053#(and (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483647) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |old(~pumpRunning~0)| 2147483647) (= 1 ~systemActive~0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483648)) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (= ~head~0.base 0) (<= 0 (+ |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483648)) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2021-11-23 03:36:25,055 WARN L312 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2021-11-23 03:36:25,055 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-11-23 03:36:25,056 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 6, 6] total 15 [2021-11-23 03:36:25,056 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1963769173] [2021-11-23 03:36:25,056 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-11-23 03:36:25,057 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2021-11-23 03:36:25,057 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:25,057 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2021-11-23 03:36:25,058 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=289, Invalid=2063, Unknown=0, NotChecked=0, Total=2352 [2021-11-23 03:36:25,059 INFO L87 Difference]: Start difference. First operand 363 states and 435 transitions. Second operand has 15 states, 11 states have (on average 8.272727272727273) internal successors, (91), 13 states have internal predecessors, (91), 7 states have call successors, (22), 4 states have call predecessors, (22), 8 states have return successors, (21), 9 states have call predecessors, (21), 7 states have call successors, (21) [2021-11-23 03:36:25,934 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:25,934 INFO L93 Difference]: Finished difference Result 469 states and 572 transitions. [2021-11-23 03:36:25,935 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 26 states. [2021-11-23 03:36:25,935 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 11 states have (on average 8.272727272727273) internal successors, (91), 13 states have internal predecessors, (91), 7 states have call successors, (22), 4 states have call predecessors, (22), 8 states have return successors, (21), 9 states have call predecessors, (21), 7 states have call successors, (21) Word has length 76 [2021-11-23 03:36:25,937 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:25,941 INFO L225 Difference]: With dead ends: 469 [2021-11-23 03:36:25,943 INFO L226 Difference]: Without dead ends: 467 [2021-11-23 03:36:25,946 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 261 GetRequests, 185 SyntacticMatches, 10 SemanticMatches, 66 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1852 ImplicationChecksByTransitivity, 7.3s TimeCoverageRelationStatistics Valid=515, Invalid=4041, Unknown=0, NotChecked=0, Total=4556 [2021-11-23 03:36:25,949 INFO L933 BasicCegarLoop]: 152 mSDtfsCounter, 411 mSDsluCounter, 563 mSDsCounter, 0 mSdLazyCounter, 417 mSolverCounterSat, 283 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 416 SdHoareTripleChecker+Valid, 594 SdHoareTripleChecker+Invalid, 700 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 283 IncrementalHoareTripleChecker+Valid, 417 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:25,950 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [416 Valid, 594 Invalid, 700 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [283 Valid, 417 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2021-11-23 03:36:25,951 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 467 states. [2021-11-23 03:36:25,982 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 467 to 414. [2021-11-23 03:36:25,984 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 414 states, 276 states have (on average 1.2246376811594204) internal successors, (338), 307 states have internal predecessors, (338), 72 states have call successors, (72), 59 states have call predecessors, (72), 65 states have return successors, (87), 70 states have call predecessors, (87), 72 states have call successors, (87) [2021-11-23 03:36:25,987 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 414 states to 414 states and 497 transitions. [2021-11-23 03:36:25,988 INFO L78 Accepts]: Start accepts. Automaton has 414 states and 497 transitions. Word has length 76 [2021-11-23 03:36:25,988 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:25,988 INFO L470 AbstractCegarLoop]: Abstraction has 414 states and 497 transitions. [2021-11-23 03:36:25,989 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 15 states, 11 states have (on average 8.272727272727273) internal successors, (91), 13 states have internal predecessors, (91), 7 states have call successors, (22), 4 states have call predecessors, (22), 8 states have return successors, (21), 9 states have call predecessors, (21), 7 states have call successors, (21) [2021-11-23 03:36:25,989 INFO L276 IsEmpty]: Start isEmpty. Operand 414 states and 497 transitions. [2021-11-23 03:36:25,991 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2021-11-23 03:36:25,991 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:25,992 INFO L514 BasicCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:26,017 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-11-23 03:36:26,203 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:26,203 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:26,204 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:26,204 INFO L85 PathProgramCache]: Analyzing trace with hash -735363460, now seen corresponding path program 1 times [2021-11-23 03:36:26,204 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:26,204 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [801340860] [2021-11-23 03:36:26,204 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:26,204 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:26,226 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:26,396 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 44 proven. 11 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2021-11-23 03:36:26,397 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:26,397 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [801340860] [2021-11-23 03:36:26,397 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [801340860] provided 0 perfect and 1 imperfect interpolant sequences [2021-11-23 03:36:26,397 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1634812146] [2021-11-23 03:36:26,398 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:26,398 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:26,398 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 [2021-11-23 03:36:26,399 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-11-23 03:36:26,416 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-11-23 03:36:26,506 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:26,509 INFO L263 TraceCheckSpWp]: Trace formula consists of 551 conjuncts, 18 conjunts are in the unsatisfiable core [2021-11-23 03:36:26,514 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-11-23 03:36:26,906 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 66 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2021-11-23 03:36:26,906 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-11-23 03:36:27,364 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 48 proven. 3 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2021-11-23 03:36:27,365 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1634812146] provided 0 perfect and 2 imperfect interpolant sequences [2021-11-23 03:36:27,365 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1153320771] [2021-11-23 03:36:27,368 INFO L159 IcfgInterpreter]: Started Sifa with 46 locations of interest [2021-11-23 03:36:27,368 INFO L166 IcfgInterpreter]: Building call graph [2021-11-23 03:36:27,369 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2021-11-23 03:36:27,369 INFO L176 IcfgInterpreter]: Starting interpretation [2021-11-23 03:36:27,369 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2021-11-23 03:36:36,208 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 309 for LOIs [2021-11-23 03:36:36,260 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2021-11-23 03:36:36,955 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 43 for LOIs [2021-11-23 03:36:37,019 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 29 for LOIs [2021-11-23 03:36:37,053 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 42 for LOIs [2021-11-23 03:36:37,064 INFO L180 IcfgInterpreter]: Interpretation finished [2021-11-23 03:36:43,241 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '12081#(and (<= 0 |old(~pumpRunning~0)|) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (<= |old(~pumpRunning~0)| 0) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= 0 ~methaneLevelCritical~0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= 1 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (<= 2 |timeShift_getWaterLevel_#res#1|) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~pumpRunning~0 1) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2021-11-23 03:36:43,241 WARN L312 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2021-11-23 03:36:43,241 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-11-23 03:36:43,241 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 9, 9] total 27 [2021-11-23 03:36:43,241 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [924844391] [2021-11-23 03:36:43,242 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-11-23 03:36:43,242 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 27 states [2021-11-23 03:36:43,242 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:43,243 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 27 interpolants. [2021-11-23 03:36:43,244 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=420, Invalid=2550, Unknown=0, NotChecked=0, Total=2970 [2021-11-23 03:36:43,244 INFO L87 Difference]: Start difference. First operand 414 states and 497 transitions. Second operand has 27 states, 26 states have (on average 4.384615384615385) internal successors, (114), 27 states have internal predecessors, (114), 13 states have call successors, (24), 5 states have call predecessors, (24), 9 states have return successors, (25), 13 states have call predecessors, (25), 13 states have call successors, (25) [2021-11-23 03:36:46,520 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:36:46,520 INFO L93 Difference]: Finished difference Result 1339 states and 1823 transitions. [2021-11-23 03:36:46,532 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 52 states. [2021-11-23 03:36:46,533 INFO L78 Accepts]: Start accepts. Automaton has has 27 states, 26 states have (on average 4.384615384615385) internal successors, (114), 27 states have internal predecessors, (114), 13 states have call successors, (24), 5 states have call predecessors, (24), 9 states have return successors, (25), 13 states have call predecessors, (25), 13 states have call successors, (25) Word has length 96 [2021-11-23 03:36:46,534 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:36:46,548 INFO L225 Difference]: With dead ends: 1339 [2021-11-23 03:36:46,548 INFO L226 Difference]: Without dead ends: 919 [2021-11-23 03:36:46,554 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 378 GetRequests, 263 SyntacticMatches, 13 SemanticMatches, 102 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4043 ImplicationChecksByTransitivity, 8.0s TimeCoverageRelationStatistics Valid=1364, Invalid=9348, Unknown=0, NotChecked=0, Total=10712 [2021-11-23 03:36:46,555 INFO L933 BasicCegarLoop]: 141 mSDtfsCounter, 993 mSDsluCounter, 1175 mSDsCounter, 0 mSdLazyCounter, 2312 mSolverCounterSat, 774 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 994 SdHoareTripleChecker+Valid, 1086 SdHoareTripleChecker+Invalid, 3086 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 774 IncrementalHoareTripleChecker+Valid, 2312 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.5s IncrementalHoareTripleChecker+Time [2021-11-23 03:36:46,556 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [994 Valid, 1086 Invalid, 3086 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [774 Valid, 2312 Invalid, 0 Unknown, 0 Unchecked, 1.5s Time] [2021-11-23 03:36:46,558 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 919 states. [2021-11-23 03:36:46,614 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 919 to 468. [2021-11-23 03:36:46,615 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 468 states, 313 states have (on average 1.2236421725239617) internal successors, (383), 351 states have internal predecessors, (383), 78 states have call successors, (78), 66 states have call predecessors, (78), 76 states have return successors, (100), 77 states have call predecessors, (100), 78 states have call successors, (100) [2021-11-23 03:36:46,618 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 468 states to 468 states and 561 transitions. [2021-11-23 03:36:46,619 INFO L78 Accepts]: Start accepts. Automaton has 468 states and 561 transitions. Word has length 96 [2021-11-23 03:36:46,619 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:36:46,619 INFO L470 AbstractCegarLoop]: Abstraction has 468 states and 561 transitions. [2021-11-23 03:36:46,620 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 27 states, 26 states have (on average 4.384615384615385) internal successors, (114), 27 states have internal predecessors, (114), 13 states have call successors, (24), 5 states have call predecessors, (24), 9 states have return successors, (25), 13 states have call predecessors, (25), 13 states have call successors, (25) [2021-11-23 03:36:46,620 INFO L276 IsEmpty]: Start isEmpty. Operand 468 states and 561 transitions. [2021-11-23 03:36:46,627 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2021-11-23 03:36:46,628 INFO L506 BasicCegarLoop]: Found error trace [2021-11-23 03:36:46,628 INFO L514 BasicCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:36:46,660 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-11-23 03:36:46,853 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-11-23 03:36:46,854 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-11-23 03:36:46,855 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-11-23 03:36:46,855 INFO L85 PathProgramCache]: Analyzing trace with hash -1954110850, now seen corresponding path program 1 times [2021-11-23 03:36:46,855 INFO L121 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2021-11-23 03:36:46,855 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [499238692] [2021-11-23 03:36:46,855 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:46,855 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-11-23 03:36:46,888 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:47,185 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 32 proven. 27 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2021-11-23 03:36:47,186 INFO L139 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2021-11-23 03:36:47,186 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [499238692] [2021-11-23 03:36:47,186 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [499238692] provided 0 perfect and 1 imperfect interpolant sequences [2021-11-23 03:36:47,186 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1298193146] [2021-11-23 03:36:47,186 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-11-23 03:36:47,186 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-11-23 03:36:47,186 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 [2021-11-23 03:36:47,187 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-11-23 03:36:47,211 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2021-11-23 03:36:47,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-11-23 03:36:47,305 INFO L263 TraceCheckSpWp]: Trace formula consists of 565 conjuncts, 30 conjunts are in the unsatisfiable core [2021-11-23 03:36:47,309 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-11-23 03:36:47,773 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 62 proven. 16 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2021-11-23 03:36:47,774 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-11-23 03:36:48,496 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 54 proven. 5 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2021-11-23 03:36:48,497 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1298193146] provided 0 perfect and 2 imperfect interpolant sequences [2021-11-23 03:36:48,497 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [754259506] [2021-11-23 03:36:48,505 INFO L159 IcfgInterpreter]: Started Sifa with 46 locations of interest [2021-11-23 03:36:48,505 INFO L166 IcfgInterpreter]: Building call graph [2021-11-23 03:36:48,506 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2021-11-23 03:36:48,506 INFO L176 IcfgInterpreter]: Starting interpretation [2021-11-23 03:36:48,506 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2021-11-23 03:36:53,284 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 35 for LOIs [2021-11-23 03:36:53,290 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2021-11-23 03:36:53,875 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 43 for LOIs [2021-11-23 03:36:53,923 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2021-11-23 03:36:53,949 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 42 for LOIs [2021-11-23 03:36:53,956 INFO L180 IcfgInterpreter]: Interpretation finished [2021-11-23 03:36:59,842 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '15606#(and (<= 0 |old(~pumpRunning~0)|) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (<= |old(~pumpRunning~0)| 0) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= 0 ~methaneLevelCritical~0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= 1 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (<= 2 |timeShift_getWaterLevel_#res#1|) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~pumpRunning~0 1) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2021-11-23 03:36:59,843 WARN L312 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2021-11-23 03:36:59,843 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-11-23 03:36:59,843 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [17, 11, 11] total 31 [2021-11-23 03:36:59,843 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1315810993] [2021-11-23 03:36:59,843 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-11-23 03:36:59,844 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 31 states [2021-11-23 03:36:59,844 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2021-11-23 03:36:59,845 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 31 interpolants. [2021-11-23 03:36:59,846 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=468, Invalid=2954, Unknown=0, NotChecked=0, Total=3422 [2021-11-23 03:36:59,846 INFO L87 Difference]: Start difference. First operand 468 states and 561 transitions. Second operand has 31 states, 29 states have (on average 5.068965517241379) internal successors, (147), 31 states have internal predecessors, (147), 17 states have call successors, (30), 7 states have call predecessors, (30), 12 states have return successors, (30), 17 states have call predecessors, (30), 16 states have call successors, (30) [2021-11-23 03:37:03,589 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-11-23 03:37:03,589 INFO L93 Difference]: Finished difference Result 1306 states and 1608 transitions. [2021-11-23 03:37:03,590 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 61 states. [2021-11-23 03:37:03,590 INFO L78 Accepts]: Start accepts. Automaton has has 31 states, 29 states have (on average 5.068965517241379) internal successors, (147), 31 states have internal predecessors, (147), 17 states have call successors, (30), 7 states have call predecessors, (30), 12 states have return successors, (30), 17 states have call predecessors, (30), 16 states have call successors, (30) Word has length 101 [2021-11-23 03:37:03,591 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-11-23 03:37:03,591 INFO L225 Difference]: With dead ends: 1306 [2021-11-23 03:37:03,591 INFO L226 Difference]: Without dead ends: 0 [2021-11-23 03:37:03,600 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 411 GetRequests, 280 SyntacticMatches, 16 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5337 ImplicationChecksByTransitivity, 8.0s TimeCoverageRelationStatistics Valid=1760, Invalid=11812, Unknown=0, NotChecked=0, Total=13572 [2021-11-23 03:37:03,605 INFO L933 BasicCegarLoop]: 182 mSDtfsCounter, 2617 mSDsluCounter, 955 mSDsCounter, 0 mSdLazyCounter, 2109 mSolverCounterSat, 1811 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 2618 SdHoareTripleChecker+Valid, 964 SdHoareTripleChecker+Invalid, 3920 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1811 IncrementalHoareTripleChecker+Valid, 2109 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.8s IncrementalHoareTripleChecker+Time [2021-11-23 03:37:03,606 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [2618 Valid, 964 Invalid, 3920 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1811 Valid, 2109 Invalid, 0 Unknown, 0 Unchecked, 1.8s Time] [2021-11-23 03:37:03,606 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-11-23 03:37:03,607 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-11-23 03:37:03,607 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-11-23 03:37:03,607 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-11-23 03:37:03,607 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 101 [2021-11-23 03:37:03,607 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-11-23 03:37:03,608 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-11-23 03:37:03,608 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 31 states, 29 states have (on average 5.068965517241379) internal successors, (147), 31 states have internal predecessors, (147), 17 states have call successors, (30), 7 states have call predecessors, (30), 12 states have return successors, (30), 17 states have call predecessors, (30), 16 states have call successors, (30) [2021-11-23 03:37:03,608 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-11-23 03:37:03,608 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-11-23 03:37:03,611 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-11-23 03:37:03,649 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2021-11-23 03:37:03,825 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-11-23 03:37:03,827 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-11-23 03:37:12,251 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 293 300) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 (not (<= 1 ~switchedOnBeforeTS~0)) (not (< ~waterLevel~0 3)) .cse2) (or .cse0 (not (<= 2 ~waterLevel~0)) .cse1 (not (<= ~waterLevel~0 2)) .cse2))) [2021-11-23 03:37:12,251 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 293 300) no Hoare annotation was computed. [2021-11-23 03:37:12,251 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 200 206) no Hoare annotation was computed. [2021-11-23 03:37:12,251 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 200 206) the Hoare annotation is: true [2021-11-23 03:37:12,251 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: true [2021-11-23 03:37:12,252 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2021-11-23 03:37:12,252 INFO L861 garLoopResultBuilder]: At program point L962-2(lines 962 976) the Hoare annotation is: true [2021-11-23 03:37:12,252 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 952 981) no Hoare annotation was computed. [2021-11-23 03:37:12,252 INFO L861 garLoopResultBuilder]: At program point L958(line 958) the Hoare annotation is: true [2021-11-23 03:37:12,252 INFO L858 garLoopResultBuilder]: For program point L958-1(line 958) no Hoare annotation was computed. [2021-11-23 03:37:12,252 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 952 981) the Hoare annotation is: true [2021-11-23 03:37:12,253 INFO L861 garLoopResultBuilder]: At program point L977(lines 952 981) the Hoare annotation is: true [2021-11-23 03:37:12,253 INFO L858 garLoopResultBuilder]: For program point L973(line 973) no Hoare annotation was computed. [2021-11-23 03:37:12,253 INFO L858 garLoopResultBuilder]: For program point L966(lines 966 970) no Hoare annotation was computed. [2021-11-23 03:37:12,253 INFO L861 garLoopResultBuilder]: At program point L966-1(lines 966 970) the Hoare annotation is: true [2021-11-23 03:37:12,253 INFO L858 garLoopResultBuilder]: For program point L568(lines 568 574) no Hoare annotation was computed. [2021-11-23 03:37:12,253 INFO L854 garLoopResultBuilder]: At program point L279(line 279) the Hoare annotation is: (let ((.cse1 (not (< |old(~waterLevel~0)| 3))) (.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse3 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (or .cse0 .cse2 .cse3 (not (= |old(~waterLevel~0)| 2))) (or .cse3 .cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1) (or .cse3 .cse4 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse2 .cse3))) [2021-11-23 03:37:12,254 INFO L854 garLoopResultBuilder]: At program point L279-1(lines 260 284) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (< |old(~waterLevel~0)| 3))) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (= ~pumpRunning~0 0)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= ~pumpRunning~0 1)) (.cse9 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (let ((.cse4 (= ~waterLevel~0 1))) (or .cse2 .cse3 (and .cse4 .cse5 .cse6) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|)) (and .cse7 .cse4 .cse5))) (or .cse0 (and .cse7 .cse8) .cse2 (and (<= 2 ~waterLevel~0) .cse8 .cse6) .cse1) (or .cse2 .cse3 (and .cse7 .cse8 .cse5) (and .cse8 .cse5 .cse6) (not (<= |old(~waterLevel~0)| 0)) .cse9) (let ((.cse10 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse11 (< 0 |old(~waterLevel~0)|))) (or (not (= |old(~waterLevel~0)| 1)) .cse2 .cse3 (and .cse7 .cse10 .cse11 .cse5) (and .cse10 .cse11 .cse5 .cse6) .cse9)))) [2021-11-23 03:37:12,254 INFO L854 garLoopResultBuilder]: At program point L531(line 531) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (or .cse2 .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1) (or .cse2 .cse3 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse2 .cse1))) [2021-11-23 03:37:12,254 INFO L858 garLoopResultBuilder]: For program point L180-2(lines 176 198) no Hoare annotation was computed. [2021-11-23 03:37:12,255 INFO L854 garLoopResultBuilder]: At program point L565(line 565) the Hoare annotation is: (let ((.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse9 (not (< |old(~waterLevel~0)| 3))) (.cse6 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (= ~pumpRunning~0 0)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse5 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0))) (and (let ((.cse2 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or .cse2 .cse3) .cse4 .cse5 .cse6) (and .cse7 (or .cse2 (and (<= |old(~waterLevel~0)| 0) .cse3)) .cse4 .cse5) (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (or .cse8 (and .cse7 (<= ~waterLevel~0 1) .cse3 .cse5) (not (= 0 ~systemActive~0)) .cse9) (or .cse8 .cse0 (and .cse7 (< |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2) .cse3 .cse5) .cse9) (let ((.cse10 (= ~waterLevel~0 1))) (or (and .cse10 .cse4 .cse5 .cse6) .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) (and .cse7 .cse10 .cse4 .cse5) (not (<= 2 |old(~waterLevel~0)|)))))) [2021-11-23 03:37:12,255 INFO L858 garLoopResultBuilder]: For program point L565-1(line 565) no Hoare annotation was computed. [2021-11-23 03:37:12,255 INFO L858 garLoopResultBuilder]: For program point L268(lines 268 276) no Hoare annotation was computed. [2021-11-23 03:37:12,255 INFO L854 garLoopResultBuilder]: At program point L264(lines 264 281) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse5 (= ~pumpRunning~0 1))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (or .cse2 .cse3 (and (= ~waterLevel~0 1) .cse4 .cse5) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 0) .cse6) .cse2 .cse1) (or (not (<= |old(~waterLevel~0)| 1)) .cse2 .cse3 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) .cse6) .cse4 .cse5) (not (<= 1 |old(~switchedOnBeforeTS~0)|))))) [2021-11-23 03:37:12,256 INFO L854 garLoopResultBuilder]: At program point L550(line 550) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse2 (and .cse9 (= ~pumpRunning~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (and (= ~pumpRunning~0 0) .cse9)) (.cse8 (not (= 0 ~systemActive~0))) (.cse4 (not (< |old(~waterLevel~0)| 3))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse5 .cse3 .cse4) (or .cse6 .cse7 .cse0 .cse4) (or .cse6 .cse0 (not (= |old(~waterLevel~0)| 2)) .cse5 .cse3) (or .cse6 (<= 2 ~waterLevel~0) .cse5 .cse8 .cse3 .cse4) (or .cse6 .cse7 .cse8 .cse4) (or (not (<= |old(~waterLevel~0)| 1)) .cse6 .cse0 .cse5 .cse3)))) [2021-11-23 03:37:12,256 INFO L854 garLoopResultBuilder]: At program point L550-1(line 550) the Hoare annotation is: (let ((.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (<= 1 |timeShift___utac_acc__Specification5_spec__2_#t~ret28#1|)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (and (= ~pumpRunning~0 0) .cse2)) (.cse6 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 (and .cse1 .cse2 (= ~pumpRunning~0 1)) .cse3 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse5 .cse0 .cse6) (or .cse4 .cse5 (not (= 0 ~systemActive~0)) .cse6)))) [2021-11-23 03:37:12,256 INFO L854 garLoopResultBuilder]: At program point L187-1(lines 187 193) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (and .cse5 .cse8)) (.cse9 (not (< |old(~waterLevel~0)| 3))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (= ~pumpRunning~0 1)) (.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (let ((.cse2 (= ~waterLevel~0 1))) (or .cse0 .cse1 (and .cse2 .cse3 .cse4) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|)) (and .cse5 .cse2 .cse3))) (or .cse6 .cse7 .cse0 (and (<= 2 ~waterLevel~0) .cse8 .cse4) .cse9) (or .cse6 .cse7 (not (= 0 ~systemActive~0)) .cse9) (or .cse0 .cse1 (and .cse5 .cse8 .cse3) (and .cse8 .cse3 .cse4) (not (<= |old(~waterLevel~0)| 0)) .cse10) (let ((.cse11 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse12 (< 0 |old(~waterLevel~0)|))) (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and .cse5 .cse11 .cse12 .cse3) (and .cse11 .cse12 .cse3 .cse4) .cse10))))) [2021-11-23 03:37:12,256 INFO L858 garLoopResultBuilder]: For program point L567(lines 567 577) no Hoare annotation was computed. [2021-11-23 03:37:12,256 INFO L858 garLoopResultBuilder]: For program point L563(lines 563 580) no Hoare annotation was computed. [2021-11-23 03:37:12,257 INFO L854 garLoopResultBuilder]: At program point L274(line 274) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse5 (= ~pumpRunning~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (or .cse2 .cse3 (and (= ~waterLevel~0 1) .cse4 .cse5) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse2 .cse3 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4 .cse5) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse2 .cse1))) [2021-11-23 03:37:12,257 INFO L854 garLoopResultBuilder]: At program point L563-1(lines 555 583) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0)) (.cse2 (= 1 ~systemActive~0))) (let ((.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse8 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse11 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not .cse2)) (.cse9 (= ~pumpRunning~0 1)) (.cse12 (and .cse1 .cse2 .cse4 .cse6)) (.cse13 (not (< |old(~waterLevel~0)| 3)))) (and (let ((.cse3 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)))) (or .cse0 (and .cse1 .cse2 (or .cse3 (and (<= |old(~waterLevel~0)| 0) .cse4)) .cse5 .cse6) .cse7 .cse8 (and (<= ~waterLevel~0 0) (or .cse3 .cse4) .cse5 .cse6 .cse9) (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (let ((.cse10 (= ~waterLevel~0 1))) (or (and .cse10 .cse5 .cse6 .cse9) .cse7 (and .cse1 .cse2 .cse10 .cse5 .cse6) .cse8 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|)))) (or .cse0 .cse11 .cse7 .cse12 .cse13) (or .cse11 (and .cse1 .cse4 .cse6) (not (= 0 ~systemActive~0)) .cse13) (or .cse11 .cse7 (and .cse4 .cse6 .cse9) .cse12 .cse13)))) [2021-11-23 03:37:12,257 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 173 199) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse2 (and .cse9 (= ~pumpRunning~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (and (= ~pumpRunning~0 0) .cse9)) (.cse8 (not (= 0 ~systemActive~0))) (.cse4 (not (< |old(~waterLevel~0)| 3))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse5 .cse3 .cse4) (or .cse6 .cse7 .cse0 .cse4) (or .cse6 .cse0 (not (= |old(~waterLevel~0)| 2)) .cse5 .cse3) (or .cse6 (<= 2 ~waterLevel~0) .cse5 .cse8 .cse3 .cse4) (or .cse6 .cse7 .cse8 .cse4) (or (not (<= |old(~waterLevel~0)| 1)) .cse6 .cse0 .cse5 .cse3)))) [2021-11-23 03:37:12,258 INFO L854 garLoopResultBuilder]: At program point L270(line 270) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse5 (= ~pumpRunning~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 (not (= 0 ~systemActive~0)) .cse1) (or .cse2 .cse3 (and (= ~waterLevel~0 1) .cse4 .cse5) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse2 .cse3 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4 .cse5) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse2 .cse1))) [2021-11-23 03:37:12,258 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 173 199) no Hoare annotation was computed. [2021-11-23 03:37:12,258 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 531) no Hoare annotation was computed. [2021-11-23 03:37:12,258 INFO L854 garLoopResultBuilder]: At program point L477(lines 430 479) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2021-11-23 03:37:12,258 INFO L858 garLoopResultBuilder]: For program point L440(lines 440 446) no Hoare annotation was computed. [2021-11-23 03:37:12,259 INFO L858 garLoopResultBuilder]: For program point L440-1(lines 440 446) no Hoare annotation was computed. [2021-11-23 03:37:12,259 INFO L858 garLoopResultBuilder]: For program point L399(lines 399 405) no Hoare annotation was computed. [2021-11-23 03:37:12,259 INFO L854 garLoopResultBuilder]: At program point L399-1(lines 399 405) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (< ~waterLevel~0 3)) [2021-11-23 03:37:12,259 INFO L861 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2021-11-23 03:37:12,259 INFO L861 garLoopResultBuilder]: At program point L483(lines 420 487) the Hoare annotation is: true [2021-11-23 03:37:12,259 INFO L858 garLoopResultBuilder]: For program point L450(lines 450 456) no Hoare annotation was computed. [2021-11-23 03:37:12,260 INFO L858 garLoopResultBuilder]: For program point L450-1(lines 450 456) no Hoare annotation was computed. [2021-11-23 03:37:12,260 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-11-23 03:37:12,260 INFO L854 garLoopResultBuilder]: At program point L442(line 442) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2021-11-23 03:37:12,260 INFO L854 garLoopResultBuilder]: At program point L401(line 401) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) (< ~waterLevel~0 3) .cse2) (and (<= 2 ~waterLevel~0) .cse0 .cse1 (<= ~waterLevel~0 2) .cse2))) [2021-11-23 03:37:12,260 INFO L854 garLoopResultBuilder]: At program point L480(lines 429 481) the Hoare annotation is: false [2021-11-23 03:37:12,260 INFO L858 garLoopResultBuilder]: For program point L468(lines 468 474) no Hoare annotation was computed. [2021-11-23 03:37:12,261 INFO L854 garLoopResultBuilder]: At program point L468-2(lines 460 475) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2021-11-23 03:37:12,261 INFO L858 garLoopResultBuilder]: For program point L431(lines 430 479) no Hoare annotation was computed. [2021-11-23 03:37:12,261 INFO L854 garLoopResultBuilder]: At program point L460(lines 460 475) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2021-11-23 03:37:12,261 INFO L854 garLoopResultBuilder]: At program point L1034(lines 1034 1041) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2021-11-23 03:37:12,261 INFO L861 garLoopResultBuilder]: At program point L1034-2(lines 1034 1041) the Hoare annotation is: true [2021-11-23 03:37:12,262 INFO L854 garLoopResultBuilder]: At program point L452(line 452) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2021-11-23 03:37:12,262 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 208 232) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,262 INFO L854 garLoopResultBuilder]: At program point L222(line 222) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (= ~pumpRunning~0 0) (or (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0))) (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2))) [2021-11-23 03:37:12,262 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 208 232) no Hoare annotation was computed. [2021-11-23 03:37:12,263 INFO L854 garLoopResultBuilder]: At program point L216(lines 216 224) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (= ~pumpRunning~0 0) (or (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0))) (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2))) [2021-11-23 03:37:12,263 INFO L854 garLoopResultBuilder]: At program point L212(lines 212 229) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,263 INFO L854 garLoopResultBuilder]: At program point L227(line 227) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,263 INFO L858 garLoopResultBuilder]: For program point L227-1(lines 208 232) no Hoare annotation was computed. [2021-11-23 03:37:12,263 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2021-11-23 03:37:12,264 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse2 (not (= 0 ~systemActive~0))) (.cse4 (not (= ~pumpRunning~0 1))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse1 .cse5 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 2)) .cse1 .cse2) (or .cse3 .cse4 .cse1 (not (<= 1 ~switchedOnBeforeTS~0)) (not (< |old(~waterLevel~0)| 3))) (or .cse0 .cse3 .cse1 .cse5))) [2021-11-23 03:37:12,264 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 234 258) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,264 INFO L854 garLoopResultBuilder]: At program point L248(line 248) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,264 INFO L854 garLoopResultBuilder]: At program point L244(line 244) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,264 INFO L858 garLoopResultBuilder]: For program point L242(lines 242 250) no Hoare annotation was computed. [2021-11-23 03:37:12,265 INFO L854 garLoopResultBuilder]: At program point L238(lines 238 255) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2021-11-23 03:37:12,265 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 234 258) no Hoare annotation was computed. [2021-11-23 03:37:12,265 INFO L854 garLoopResultBuilder]: At program point L253(line 253) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2))) [2021-11-23 03:37:12,265 INFO L858 garLoopResultBuilder]: For program point L253-1(lines 234 258) no Hoare annotation was computed. [2021-11-23 03:37:12,265 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 312 320) no Hoare annotation was computed. [2021-11-23 03:37:12,266 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 312 320) the Hoare annotation is: true [2021-11-23 03:37:12,269 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-11-23 03:37:12,270 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-11-23 03:37:12,321 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 23.11 03:37:12 BoogieIcfgContainer [2021-11-23 03:37:12,321 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-11-23 03:37:12,321 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-11-23 03:37:12,322 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-11-23 03:37:12,322 INFO L275 PluginConnector]: Witness Printer initialized [2021-11-23 03:37:12,332 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 03:36:03" (3/4) ... [2021-11-23 03:37:12,335 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-11-23 03:37:12,341 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-11-23 03:37:12,341 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-11-23 03:37:12,341 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-11-23 03:37:12,341 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-11-23 03:37:12,341 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-11-23 03:37:12,342 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-11-23 03:37:12,342 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-11-23 03:37:12,342 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2021-11-23 03:37:12,342 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2021-11-23 03:37:12,361 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 78 nodes and edges [2021-11-23 03:37:12,362 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 30 nodes and edges [2021-11-23 03:37:12,363 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2021-11-23 03:37:12,363 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-11-23 03:37:12,364 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-11-23 03:37:12,365 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-11-23 03:37:12,365 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-11-23 03:37:12,395 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || ((1 <= aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((pumpRunning == \old(pumpRunning) && 1 <= aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) [2021-11-23 03:37:12,396 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) [2021-11-23 03:37:12,397 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(waterLevel) <= 1) || ((((pumpRunning == 0 && 1 == systemActive) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || (\old(waterLevel) <= 0 && \old(waterLevel) == waterLevel))) && 1 <= switchedOnBeforeTS) && tmp == waterLevel)) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && tmp == waterLevel) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) && ((((((((waterLevel == 1 && 1 <= switchedOnBeforeTS) && tmp == waterLevel) && pumpRunning == 1) || !(1 == systemActive)) || ((((pumpRunning == 0 && 1 == systemActive) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && tmp == waterLevel)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((\old(waterLevel) == waterLevel && tmp == waterLevel) && pumpRunning == 1)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(\old(waterLevel) < 3)) [2021-11-23 03:37:12,398 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) [2021-11-23 03:37:12,398 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3)) [2021-11-23 03:37:12,398 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) [2021-11-23 03:37:12,398 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2021-11-23 03:37:12,399 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2021-11-23 03:37:12,406 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && (2 <= waterLevel || tmp == 0))) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) [2021-11-23 03:37:12,459 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/witness.graphml [2021-11-23 03:37:12,460 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-11-23 03:37:12,460 INFO L158 Benchmark]: Toolchain (without parser) took 70736.40ms. Allocated memory was 134.2MB in the beginning and 616.6MB in the end (delta: 482.3MB). Free memory was 100.3MB in the beginning and 457.3MB in the end (delta: -357.0MB). Peak memory consumption was 124.8MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,461 INFO L158 Benchmark]: CDTParser took 0.25ms. Allocated memory is still 83.9MB. Free memory was 39.8MB in the beginning and 39.7MB in the end (delta: 76.9kB). There was no memory consumed. Max. memory is 16.1GB. [2021-11-23 03:37:12,461 INFO L158 Benchmark]: CACSL2BoogieTranslator took 586.83ms. Allocated memory is still 134.2MB. Free memory was 100.3MB in the beginning and 100.6MB in the end (delta: -281.2kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,461 INFO L158 Benchmark]: Boogie Procedure Inliner took 63.50ms. Allocated memory is still 134.2MB. Free memory was 100.6MB in the beginning and 98.0MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,462 INFO L158 Benchmark]: Boogie Preprocessor took 53.30ms. Allocated memory is still 134.2MB. Free memory was 98.0MB in the beginning and 96.4MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,462 INFO L158 Benchmark]: RCFGBuilder took 710.51ms. Allocated memory is still 134.2MB. Free memory was 96.4MB in the beginning and 72.4MB in the end (delta: 24.0MB). Peak memory consumption was 23.1MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,463 INFO L158 Benchmark]: TraceAbstraction took 69177.46ms. Allocated memory was 134.2MB in the beginning and 616.6MB in the end (delta: 482.3MB). Free memory was 71.7MB in the beginning and 465.7MB in the end (delta: -394.0MB). Peak memory consumption was 343.6MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,464 INFO L158 Benchmark]: Witness Printer took 138.27ms. Allocated memory is still 616.6MB. Free memory was 464.6MB in the beginning and 457.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-11-23 03:37:12,466 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.25ms. Allocated memory is still 83.9MB. Free memory was 39.8MB in the beginning and 39.7MB in the end (delta: 76.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 586.83ms. Allocated memory is still 134.2MB. Free memory was 100.3MB in the beginning and 100.6MB in the end (delta: -281.2kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 63.50ms. Allocated memory is still 134.2MB. Free memory was 100.6MB in the beginning and 98.0MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 53.30ms. Allocated memory is still 134.2MB. Free memory was 98.0MB in the beginning and 96.4MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 710.51ms. Allocated memory is still 134.2MB. Free memory was 96.4MB in the beginning and 72.4MB in the end (delta: 24.0MB). Peak memory consumption was 23.1MB. Max. memory is 16.1GB. * TraceAbstraction took 69177.46ms. Allocated memory was 134.2MB in the beginning and 616.6MB in the end (delta: 482.3MB). Free memory was 71.7MB in the beginning and 465.7MB in the end (delta: -394.0MB). Peak memory consumption was 343.6MB. Max. memory is 16.1GB. * Witness Printer took 138.27ms. Allocated memory is still 616.6MB. Free memory was 464.6MB in the beginning and 457.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 531]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 74 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 69.0s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 9.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 8.4s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 4672 SdHoareTripleChecker+Valid, 4.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 4651 mSDsluCounter, 4208 SdHoareTripleChecker+Invalid, 3.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3725 mSDsCounter, 3007 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 5752 IncrementalHoareTripleChecker+Invalid, 8759 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 3007 mSolverCounterUnsat, 1169 mSDtfsCounter, 5752 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1177 GetRequests, 820 SyntacticMatches, 39 SemanticMatches, 318 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 11275 ImplicationChecksByTransitivity, 23.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=566occurred in iteration=6, InterpolantAutomatonStates: 183, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 11 MinimizatonAttempts, 596 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 2093 PreInvPairs, 2415 NumberOfFragments, 2638 HoareAnnotationTreeSize, 2093 FomulaSimplifications, 19952 FormulaSimplificationTreeSizeReduction, 1.9s HoareSimplificationTime, 44 FomulaSimplificationsInter, 62999 FormulaSimplificationTreeSizeReductionInter, 6.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.6s SatisfiabilityAnalysisTime, 4.0s InterpolantComputationTime, 928 NumberOfCodeBlocks, 928 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1183 ConstructedInterpolants, 0 QuantifiedInterpolants, 3391 SizeOfPredicates, 26 NumberOfNonLiveVariables, 2064 ConjunctsInSsa, 60 ConjunctsInUnsatCore, 18 InterpolantComputations, 8 PerfectInterpolantSequences, 562/660 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 1034]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 420]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 399]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && splverifierCounter == 0) && waterLevel < 3 - InvariantResult [Line: 238]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: 260]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 264]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 555]: Loop Invariant Derived loop invariant: ((((((((!(\old(waterLevel) <= 1) || ((((pumpRunning == 0 && 1 == systemActive) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || (\old(waterLevel) <= 0 && \old(waterLevel) == waterLevel))) && 1 <= switchedOnBeforeTS) && tmp == waterLevel)) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && tmp == waterLevel) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) && ((((((((waterLevel == 1 && 1 <= switchedOnBeforeTS) && tmp == waterLevel) && pumpRunning == 1) || !(1 == systemActive)) || ((((pumpRunning == 0 && 1 == systemActive) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && tmp == waterLevel)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((\old(waterLevel) == waterLevel && tmp == waterLevel) && pumpRunning == 1)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == waterLevel)) || !(\old(waterLevel) < 3)) - InvariantResult [Line: 1034]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 460]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel < 3) || ((((1 == systemActive && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && pumpRunning == 1)) || (((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive) && waterLevel < 3)) || ((((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && pumpRunning == 1) - InvariantResult [Line: 952]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 187]: Loop Invariant Derived loop invariant: ((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel < 3) || ((((1 == systemActive && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && pumpRunning == 1)) || (((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive) && waterLevel < 3)) || ((((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && pumpRunning == 1) - InvariantResult [Line: 962]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 216]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && (2 <= waterLevel || tmp == 0))) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3)) - InvariantResult [Line: 429]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 550]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || ((1 <= aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((pumpRunning == \old(pumpRunning) && 1 <= aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(\old(waterLevel) < 3)) - InvariantResult [Line: 212]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) RESULT: Ultimate proved your program to be correct! [2021-11-23 03:37:12,546 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aad4d5d9-8841-4481-8b35-164dbc5b792a/bin/utaipan-EQgc7hIp5V/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE