./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash e91d5c860cfea17112af53939b2fffb1e4c536355098377ab18c754994d1bc2b --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-02 20:58:46,742 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-02 20:58:46,745 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-02 20:58:46,791 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-02 20:58:46,792 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-02 20:58:46,796 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-02 20:58:46,798 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-02 20:58:46,801 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-02 20:58:46,807 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-02 20:58:46,808 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-02 20:58:46,809 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-02 20:58:46,810 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-02 20:58:46,810 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-02 20:58:46,811 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-02 20:58:46,812 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-02 20:58:46,813 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-02 20:58:46,814 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-02 20:58:46,814 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-02 20:58:46,816 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-02 20:58:46,822 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-02 20:58:46,828 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-02 20:58:46,835 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-02 20:58:46,838 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-02 20:58:46,840 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-02 20:58:46,845 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-02 20:58:46,849 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-02 20:58:46,849 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-02 20:58:46,851 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-02 20:58:46,851 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-02 20:58:46,852 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-02 20:58:46,853 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-02 20:58:46,855 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-02 20:58:46,857 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-02 20:58:46,858 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-02 20:58:46,859 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-02 20:58:46,859 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-02 20:58:46,860 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-02 20:58:46,860 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-02 20:58:46,860 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-02 20:58:46,861 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-02 20:58:46,862 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-02 20:58:46,863 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-02 20:58:46,904 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-02 20:58:46,904 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-02 20:58:46,905 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-02 20:58:46,905 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-02 20:58:46,906 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-02 20:58:46,906 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-02 20:58:46,907 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-02 20:58:46,907 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-02 20:58:46,907 INFO L138 SettingsManager]: * Use SBE=true [2022-11-02 20:58:46,908 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-02 20:58:46,909 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-02 20:58:46,909 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-02 20:58:46,909 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-02 20:58:46,909 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-02 20:58:46,910 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-02 20:58:46,910 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-02 20:58:46,910 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-02 20:58:46,910 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-02 20:58:46,911 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-02 20:58:46,911 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-02 20:58:46,911 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-02 20:58:46,911 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-02 20:58:46,911 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-02 20:58:46,912 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-02 20:58:46,912 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:58:46,912 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-02 20:58:46,912 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-02 20:58:46,913 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-02 20:58:46,913 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-02 20:58:46,913 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-02 20:58:46,913 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-02 20:58:46,914 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-02 20:58:46,914 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-02 20:58:46,914 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> e91d5c860cfea17112af53939b2fffb1e4c536355098377ab18c754994d1bc2b [2022-11-02 20:58:47,217 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-02 20:58:47,245 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-02 20:58:47,248 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-02 20:58:47,249 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-02 20:58:47,250 INFO L275 PluginConnector]: CDTParser initialized [2022-11-02 20:58:47,251 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c [2022-11-02 20:58:47,327 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/data/655018279/7c30fdfcb1004945abdf37631cf38108/FLAG76c74af12 [2022-11-02 20:58:47,898 INFO L306 CDTParser]: Found 1 translation units. [2022-11-02 20:58:47,899 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c [2022-11-02 20:58:47,916 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/data/655018279/7c30fdfcb1004945abdf37631cf38108/FLAG76c74af12 [2022-11-02 20:58:48,198 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/data/655018279/7c30fdfcb1004945abdf37631cf38108 [2022-11-02 20:58:48,201 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-02 20:58:48,202 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-02 20:58:48,204 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-02 20:58:48,204 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-02 20:58:48,207 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-02 20:58:48,208 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,209 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@3b4d9151 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48, skipping insertion in model container [2022-11-02 20:58:48,210 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,217 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-02 20:58:48,253 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-02 20:58:48,545 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c[15987,16000] [2022-11-02 20:58:48,582 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:58:48,596 INFO L203 MainTranslator]: Completed pre-run [2022-11-02 20:58:48,681 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c[15987,16000] [2022-11-02 20:58:48,690 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:58:48,705 INFO L208 MainTranslator]: Completed translation [2022-11-02 20:58:48,706 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48 WrapperNode [2022-11-02 20:58:48,706 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-02 20:58:48,707 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-02 20:58:48,707 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-02 20:58:48,708 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-02 20:58:48,715 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,727 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,753 INFO L138 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 281 [2022-11-02 20:58:48,754 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-02 20:58:48,755 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-02 20:58:48,755 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-02 20:58:48,755 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-02 20:58:48,764 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,764 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,766 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,766 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,771 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,776 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,778 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,779 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,781 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-02 20:58:48,782 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-02 20:58:48,782 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-02 20:58:48,782 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-02 20:58:48,783 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (1/1) ... [2022-11-02 20:58:48,805 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:58:48,831 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:58:48,847 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-02 20:58:48,858 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-02 20:58:48,895 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-02 20:58:48,895 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-02 20:58:48,895 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-02 20:58:48,895 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-02 20:58:48,896 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-02 20:58:48,896 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-02 20:58:48,896 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-02 20:58:48,897 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:58:48,898 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:58:48,898 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-02 20:58:48,899 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-02 20:58:48,899 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-02 20:58:48,899 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-02 20:58:48,899 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-02 20:58:48,899 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-02 20:58:48,899 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-02 20:58:48,899 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-02 20:58:48,900 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-02 20:58:48,900 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-02 20:58:48,900 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-02 20:58:49,010 INFO L235 CfgBuilder]: Building ICFG [2022-11-02 20:58:49,013 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-02 20:58:49,408 INFO L276 CfgBuilder]: Performing block encoding [2022-11-02 20:58:49,415 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-02 20:58:49,421 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-02 20:58:49,424 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:58:49 BoogieIcfgContainer [2022-11-02 20:58:49,424 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-02 20:58:49,426 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-02 20:58:49,426 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-02 20:58:49,431 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-02 20:58:49,432 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 02.11 08:58:48" (1/3) ... [2022-11-02 20:58:49,433 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1df714b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:58:49, skipping insertion in model container [2022-11-02 20:58:49,433 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:58:48" (2/3) ... [2022-11-02 20:58:49,434 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1df714b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:58:49, skipping insertion in model container [2022-11-02 20:58:49,434 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:58:49" (3/3) ... [2022-11-02 20:58:49,435 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product53.cil.c [2022-11-02 20:58:49,454 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-02 20:58:49,454 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-02 20:58:49,526 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-02 20:58:49,541 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@5a80d35f, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-02 20:58:49,542 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-02 20:58:49,549 INFO L276 IsEmpty]: Start isEmpty. Operand has 95 states, 71 states have (on average 1.3943661971830985) internal successors, (99), 81 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-02 20:58:49,559 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-02 20:58:49,559 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:49,560 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:49,561 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:49,568 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:49,569 INFO L85 PathProgramCache]: Analyzing trace with hash 1446250138, now seen corresponding path program 1 times [2022-11-02 20:58:49,578 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:49,578 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1551609324] [2022-11-02 20:58:49,579 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:49,579 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:49,752 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:49,877 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:49,878 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:49,878 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1551609324] [2022-11-02 20:58:49,879 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1551609324] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:49,880 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:49,880 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-02 20:58:49,882 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1327017416] [2022-11-02 20:58:49,884 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:49,889 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-02 20:58:49,890 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:49,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-02 20:58:49,925 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:58:49,929 INFO L87 Difference]: Start difference. First operand has 95 states, 71 states have (on average 1.3943661971830985) internal successors, (99), 81 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:49,994 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:49,994 INFO L93 Difference]: Finished difference Result 182 states and 249 transitions. [2022-11-02 20:58:49,995 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-02 20:58:49,997 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-02 20:58:49,998 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:50,012 INFO L225 Difference]: With dead ends: 182 [2022-11-02 20:58:50,012 INFO L226 Difference]: Without dead ends: 86 [2022-11-02 20:58:50,017 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:58:50,022 INFO L413 NwaCegarLoop]: 121 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 121 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:50,023 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:58:50,043 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 86 states. [2022-11-02 20:58:50,103 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 86 to 86. [2022-11-02 20:58:50,105 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 64 states have (on average 1.328125) internal successors, (85), 73 states have internal predecessors, (85), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-02 20:58:50,110 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 112 transitions. [2022-11-02 20:58:50,111 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 112 transitions. Word has length 19 [2022-11-02 20:58:50,112 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:50,112 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 112 transitions. [2022-11-02 20:58:50,112 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:50,112 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 112 transitions. [2022-11-02 20:58:50,114 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-02 20:58:50,114 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:50,115 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:50,115 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-02 20:58:50,115 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:50,116 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:50,116 INFO L85 PathProgramCache]: Analyzing trace with hash -1941246016, now seen corresponding path program 1 times [2022-11-02 20:58:50,116 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:50,117 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1043345943] [2022-11-02 20:58:50,117 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:50,117 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:50,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:50,250 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:50,251 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:50,251 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1043345943] [2022-11-02 20:58:50,251 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1043345943] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:50,252 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:50,252 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-02 20:58:50,252 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [583521001] [2022-11-02 20:58:50,252 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:50,253 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-02 20:58:50,254 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:50,254 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-02 20:58:50,255 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:58:50,255 INFO L87 Difference]: Start difference. First operand 86 states and 112 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:50,271 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:50,271 INFO L93 Difference]: Finished difference Result 138 states and 180 transitions. [2022-11-02 20:58:50,272 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-02 20:58:50,272 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-02 20:58:50,273 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:50,274 INFO L225 Difference]: With dead ends: 138 [2022-11-02 20:58:50,274 INFO L226 Difference]: Without dead ends: 77 [2022-11-02 20:58:50,275 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:58:50,276 INFO L413 NwaCegarLoop]: 99 mSDtfsCounter, 12 mSDsluCounter, 83 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 182 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:50,277 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [15 Valid, 182 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:58:50,278 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 77 states. [2022-11-02 20:58:50,285 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 77 to 77. [2022-11-02 20:58:50,286 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 77 states, 58 states have (on average 1.3448275862068966) internal successors, (78), 67 states have internal predecessors, (78), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-02 20:58:50,287 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 77 states to 77 states and 100 transitions. [2022-11-02 20:58:50,287 INFO L78 Accepts]: Start accepts. Automaton has 77 states and 100 transitions. Word has length 20 [2022-11-02 20:58:50,287 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:50,288 INFO L495 AbstractCegarLoop]: Abstraction has 77 states and 100 transitions. [2022-11-02 20:58:50,288 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:50,288 INFO L276 IsEmpty]: Start isEmpty. Operand 77 states and 100 transitions. [2022-11-02 20:58:50,289 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-02 20:58:50,289 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:50,290 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:50,290 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-02 20:58:50,290 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:50,291 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:50,291 INFO L85 PathProgramCache]: Analyzing trace with hash 626660710, now seen corresponding path program 1 times [2022-11-02 20:58:50,291 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:50,291 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [863027184] [2022-11-02 20:58:50,292 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:50,292 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:50,312 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:50,529 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:50,530 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:50,530 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [863027184] [2022-11-02 20:58:50,530 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [863027184] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:50,530 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:50,531 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:58:50,531 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1877583849] [2022-11-02 20:58:50,531 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:50,532 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:58:50,532 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:50,532 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:58:50,533 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:58:50,533 INFO L87 Difference]: Start difference. First operand 77 states and 100 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:50,673 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:50,673 INFO L93 Difference]: Finished difference Result 147 states and 194 transitions. [2022-11-02 20:58:50,674 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:58:50,674 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-11-02 20:58:50,674 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:50,675 INFO L225 Difference]: With dead ends: 147 [2022-11-02 20:58:50,676 INFO L226 Difference]: Without dead ends: 77 [2022-11-02 20:58:50,676 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-02 20:58:50,678 INFO L413 NwaCegarLoop]: 93 mSDtfsCounter, 126 mSDsluCounter, 116 mSDsCounter, 0 mSdLazyCounter, 49 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 126 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 59 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 49 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:50,678 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [126 Valid, 209 Invalid, 59 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 49 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:58:50,679 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 77 states. [2022-11-02 20:58:50,688 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 77 to 77. [2022-11-02 20:58:50,688 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 77 states, 58 states have (on average 1.3275862068965518) internal successors, (77), 67 states have internal predecessors, (77), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-02 20:58:50,689 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 77 states to 77 states and 99 transitions. [2022-11-02 20:58:50,689 INFO L78 Accepts]: Start accepts. Automaton has 77 states and 99 transitions. Word has length 24 [2022-11-02 20:58:50,689 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:50,690 INFO L495 AbstractCegarLoop]: Abstraction has 77 states and 99 transitions. [2022-11-02 20:58:50,690 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:58:50,690 INFO L276 IsEmpty]: Start isEmpty. Operand 77 states and 99 transitions. [2022-11-02 20:58:50,691 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-02 20:58:50,691 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:50,692 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:50,692 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-02 20:58:50,692 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:50,693 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:50,693 INFO L85 PathProgramCache]: Analyzing trace with hash 222843713, now seen corresponding path program 1 times [2022-11-02 20:58:50,693 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:50,693 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [790867813] [2022-11-02 20:58:50,693 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:50,694 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:50,710 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:50,777 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2022-11-02 20:58:50,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:50,780 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:50,780 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:50,780 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [790867813] [2022-11-02 20:58:50,781 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [790867813] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:50,781 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:50,781 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-02 20:58:50,781 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [890941764] [2022-11-02 20:58:50,795 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:50,796 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-02 20:58:50,797 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:50,798 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-02 20:58:50,798 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-02 20:58:50,799 INFO L87 Difference]: Start difference. First operand 77 states and 99 transitions. Second operand has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-02 20:58:51,016 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:51,016 INFO L93 Difference]: Finished difference Result 217 states and 282 transitions. [2022-11-02 20:58:51,017 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:58:51,017 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 33 [2022-11-02 20:58:51,018 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:51,020 INFO L225 Difference]: With dead ends: 217 [2022-11-02 20:58:51,022 INFO L226 Difference]: Without dead ends: 147 [2022-11-02 20:58:51,023 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:58:51,028 INFO L413 NwaCegarLoop]: 102 mSDtfsCounter, 137 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 65 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 140 SdHoareTripleChecker+Valid, 208 SdHoareTripleChecker+Invalid, 101 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 65 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:51,031 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [140 Valid, 208 Invalid, 101 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 65 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:58:51,033 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 147 states. [2022-11-02 20:58:51,064 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 147 to 141. [2022-11-02 20:58:51,066 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 141 states, 108 states have (on average 1.287037037037037) internal successors, (139), 116 states have internal predecessors, (139), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-02 20:58:51,067 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 141 states to 141 states and 178 transitions. [2022-11-02 20:58:51,067 INFO L78 Accepts]: Start accepts. Automaton has 141 states and 178 transitions. Word has length 33 [2022-11-02 20:58:51,067 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:51,068 INFO L495 AbstractCegarLoop]: Abstraction has 141 states and 178 transitions. [2022-11-02 20:58:51,068 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-02 20:58:51,068 INFO L276 IsEmpty]: Start isEmpty. Operand 141 states and 178 transitions. [2022-11-02 20:58:51,069 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-02 20:58:51,069 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:51,069 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:51,070 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-02 20:58:51,070 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:51,070 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:51,070 INFO L85 PathProgramCache]: Analyzing trace with hash 569930082, now seen corresponding path program 1 times [2022-11-02 20:58:51,071 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:51,071 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2098780661] [2022-11-02 20:58:51,071 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:51,071 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:51,087 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,156 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:51,160 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,173 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:51,176 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,208 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:51,208 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:51,208 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2098780661] [2022-11-02 20:58:51,208 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2098780661] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:51,209 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:51,209 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:58:51,209 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [910567617] [2022-11-02 20:58:51,209 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:51,210 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:58:51,210 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:51,210 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:58:51,210 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:58:51,211 INFO L87 Difference]: Start difference. First operand 141 states and 178 transitions. Second operand has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:58:51,372 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:51,372 INFO L93 Difference]: Finished difference Result 283 states and 365 transitions. [2022-11-02 20:58:51,372 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:58:51,373 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-11-02 20:58:51,373 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:51,374 INFO L225 Difference]: With dead ends: 283 [2022-11-02 20:58:51,374 INFO L226 Difference]: Without dead ends: 149 [2022-11-02 20:58:51,375 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-02 20:58:51,376 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 68 mSDsluCounter, 297 mSDsCounter, 0 mSdLazyCounter, 115 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 394 SdHoareTripleChecker+Invalid, 137 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 115 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:51,377 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 394 Invalid, 137 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 115 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:58:51,377 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 149 states. [2022-11-02 20:58:51,393 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 149 to 144. [2022-11-02 20:58:51,394 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 144 states, 111 states have (on average 1.2792792792792793) internal successors, (142), 119 states have internal predecessors, (142), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-02 20:58:51,395 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 144 states to 144 states and 181 transitions. [2022-11-02 20:58:51,395 INFO L78 Accepts]: Start accepts. Automaton has 144 states and 181 transitions. Word has length 43 [2022-11-02 20:58:51,396 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:51,396 INFO L495 AbstractCegarLoop]: Abstraction has 144 states and 181 transitions. [2022-11-02 20:58:51,396 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:58:51,396 INFO L276 IsEmpty]: Start isEmpty. Operand 144 states and 181 transitions. [2022-11-02 20:58:51,397 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-02 20:58:51,397 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:51,397 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:51,398 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-02 20:58:51,398 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:51,398 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:51,398 INFO L85 PathProgramCache]: Analyzing trace with hash -451138272, now seen corresponding path program 1 times [2022-11-02 20:58:51,398 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:51,399 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [739710829] [2022-11-02 20:58:51,399 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:51,399 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:51,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,541 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:51,547 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,570 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:51,582 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,636 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:51,636 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:51,637 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [739710829] [2022-11-02 20:58:51,637 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [739710829] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:51,637 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:51,637 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-02 20:58:51,637 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2038364075] [2022-11-02 20:58:51,638 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:51,638 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-02 20:58:51,638 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:51,639 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-02 20:58:51,640 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:58:51,640 INFO L87 Difference]: Start difference. First operand 144 states and 181 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:58:51,828 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:51,828 INFO L93 Difference]: Finished difference Result 294 states and 384 transitions. [2022-11-02 20:58:51,828 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-02 20:58:51,829 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-11-02 20:58:51,829 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:51,831 INFO L225 Difference]: With dead ends: 294 [2022-11-02 20:58:51,831 INFO L226 Difference]: Without dead ends: 157 [2022-11-02 20:58:51,832 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=30, Invalid=80, Unknown=0, NotChecked=0, Total=110 [2022-11-02 20:58:51,836 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 109 mSDsluCounter, 344 mSDsCounter, 0 mSdLazyCounter, 151 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 111 SdHoareTripleChecker+Valid, 440 SdHoareTripleChecker+Invalid, 180 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 151 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:51,839 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [111 Valid, 440 Invalid, 180 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 151 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:58:51,840 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 157 states. [2022-11-02 20:58:51,864 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 157 to 146. [2022-11-02 20:58:51,864 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 146 states, 113 states have (on average 1.2743362831858407) internal successors, (144), 121 states have internal predecessors, (144), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-02 20:58:51,871 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 146 states to 146 states and 183 transitions. [2022-11-02 20:58:51,871 INFO L78 Accepts]: Start accepts. Automaton has 146 states and 183 transitions. Word has length 43 [2022-11-02 20:58:51,874 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:51,874 INFO L495 AbstractCegarLoop]: Abstraction has 146 states and 183 transitions. [2022-11-02 20:58:51,875 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:58:51,875 INFO L276 IsEmpty]: Start isEmpty. Operand 146 states and 183 transitions. [2022-11-02 20:58:51,882 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-02 20:58:51,882 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:51,883 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:51,883 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-02 20:58:51,883 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:51,883 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:51,883 INFO L85 PathProgramCache]: Analyzing trace with hash 1849684318, now seen corresponding path program 1 times [2022-11-02 20:58:51,884 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:51,884 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [358470193] [2022-11-02 20:58:51,884 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:51,884 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:51,907 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:51,995 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:51,998 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,015 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:52,019 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,046 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:52,047 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:52,047 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [358470193] [2022-11-02 20:58:52,047 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [358470193] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:52,047 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:52,048 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:58:52,048 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1220218508] [2022-11-02 20:58:52,048 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:52,048 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:58:52,048 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:52,049 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:58:52,049 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:58:52,049 INFO L87 Difference]: Start difference. First operand 146 states and 183 transitions. Second operand has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:58:52,315 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:52,315 INFO L93 Difference]: Finished difference Result 407 states and 536 transitions. [2022-11-02 20:58:52,316 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:58:52,316 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 43 [2022-11-02 20:58:52,316 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:52,321 INFO L225 Difference]: With dead ends: 407 [2022-11-02 20:58:52,321 INFO L226 Difference]: Without dead ends: 268 [2022-11-02 20:58:52,322 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:58:52,329 INFO L413 NwaCegarLoop]: 141 mSDtfsCounter, 199 mSDsluCounter, 177 mSDsCounter, 0 mSdLazyCounter, 156 mSolverCounterSat, 56 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 203 SdHoareTripleChecker+Valid, 318 SdHoareTripleChecker+Invalid, 212 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 56 IncrementalHoareTripleChecker+Valid, 156 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:52,329 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [203 Valid, 318 Invalid, 212 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [56 Valid, 156 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:58:52,331 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 268 states. [2022-11-02 20:58:52,367 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 268 to 260. [2022-11-02 20:58:52,368 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 260 states, 199 states have (on average 1.256281407035176) internal successors, (250), 211 states have internal predecessors, (250), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-02 20:58:52,370 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 260 states to 260 states and 334 transitions. [2022-11-02 20:58:52,370 INFO L78 Accepts]: Start accepts. Automaton has 260 states and 334 transitions. Word has length 43 [2022-11-02 20:58:52,371 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:52,371 INFO L495 AbstractCegarLoop]: Abstraction has 260 states and 334 transitions. [2022-11-02 20:58:52,371 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:58:52,371 INFO L276 IsEmpty]: Start isEmpty. Operand 260 states and 334 transitions. [2022-11-02 20:58:52,373 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-11-02 20:58:52,373 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:52,374 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:52,374 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-02 20:58:52,374 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:52,374 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:52,374 INFO L85 PathProgramCache]: Analyzing trace with hash -784742271, now seen corresponding path program 1 times [2022-11-02 20:58:52,375 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:52,375 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1813811413] [2022-11-02 20:58:52,377 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:52,377 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:52,398 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,490 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:52,492 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,496 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:52,498 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,501 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:58:52,502 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,503 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:52,503 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:52,503 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1813811413] [2022-11-02 20:58:52,503 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1813811413] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:52,503 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:52,504 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:58:52,504 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [915299867] [2022-11-02 20:58:52,504 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:52,504 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:58:52,504 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:52,505 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:58:52,505 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:58:52,505 INFO L87 Difference]: Start difference. First operand 260 states and 334 transitions. Second operand has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:58:52,690 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:52,690 INFO L93 Difference]: Finished difference Result 513 states and 660 transitions. [2022-11-02 20:58:52,691 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:58:52,691 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 45 [2022-11-02 20:58:52,691 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:52,694 INFO L225 Difference]: With dead ends: 513 [2022-11-02 20:58:52,694 INFO L226 Difference]: Without dead ends: 260 [2022-11-02 20:58:52,695 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-02 20:58:52,696 INFO L413 NwaCegarLoop]: 90 mSDtfsCounter, 113 mSDsluCounter, 277 mSDsCounter, 0 mSdLazyCounter, 140 mSolverCounterSat, 28 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 116 SdHoareTripleChecker+Valid, 367 SdHoareTripleChecker+Invalid, 168 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 28 IncrementalHoareTripleChecker+Valid, 140 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:52,696 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [116 Valid, 367 Invalid, 168 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [28 Valid, 140 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:58:52,697 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 260 states. [2022-11-02 20:58:52,734 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 260 to 258. [2022-11-02 20:58:52,735 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 258 states, 197 states have (on average 1.248730964467005) internal successors, (246), 209 states have internal predecessors, (246), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-02 20:58:52,736 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 258 states to 258 states and 330 transitions. [2022-11-02 20:58:52,736 INFO L78 Accepts]: Start accepts. Automaton has 258 states and 330 transitions. Word has length 45 [2022-11-02 20:58:52,737 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:52,737 INFO L495 AbstractCegarLoop]: Abstraction has 258 states and 330 transitions. [2022-11-02 20:58:52,737 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:58:52,737 INFO L276 IsEmpty]: Start isEmpty. Operand 258 states and 330 transitions. [2022-11-02 20:58:52,738 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-02 20:58:52,738 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:52,738 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:52,738 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-02 20:58:52,738 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:52,738 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:52,739 INFO L85 PathProgramCache]: Analyzing trace with hash 1315447288, now seen corresponding path program 1 times [2022-11-02 20:58:52,739 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:52,739 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [22683404] [2022-11-02 20:58:52,739 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:52,739 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:52,751 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,857 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:58:52,858 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,865 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:58:52,867 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,875 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:52,877 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:52,885 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:52,885 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:52,886 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [22683404] [2022-11-02 20:58:52,886 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [22683404] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:58:52,886 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:58:52,886 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-02 20:58:52,886 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [482185398] [2022-11-02 20:58:52,887 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:58:52,887 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-02 20:58:52,887 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:52,887 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-02 20:58:52,888 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:58:52,888 INFO L87 Difference]: Start difference. First operand 258 states and 330 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-02 20:58:53,346 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:53,347 INFO L93 Difference]: Finished difference Result 538 states and 711 transitions. [2022-11-02 20:58:53,347 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-02 20:58:53,347 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2022-11-02 20:58:53,348 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:53,350 INFO L225 Difference]: With dead ends: 538 [2022-11-02 20:58:53,350 INFO L226 Difference]: Without dead ends: 332 [2022-11-02 20:58:53,351 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 58 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-11-02 20:58:53,352 INFO L413 NwaCegarLoop]: 145 mSDtfsCounter, 201 mSDsluCounter, 338 mSDsCounter, 0 mSdLazyCounter, 383 mSolverCounterSat, 70 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 202 SdHoareTripleChecker+Valid, 483 SdHoareTripleChecker+Invalid, 453 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 70 IncrementalHoareTripleChecker+Valid, 383 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:53,352 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [202 Valid, 483 Invalid, 453 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [70 Valid, 383 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-02 20:58:53,353 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 332 states. [2022-11-02 20:58:53,378 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 332 to 297. [2022-11-02 20:58:53,379 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 297 states, 228 states have (on average 1.2236842105263157) internal successors, (279), 244 states have internal predecessors, (279), 32 states have call successors, (32), 28 states have call predecessors, (32), 36 states have return successors, (69), 34 states have call predecessors, (69), 32 states have call successors, (69) [2022-11-02 20:58:53,381 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 297 states to 297 states and 380 transitions. [2022-11-02 20:58:53,381 INFO L78 Accepts]: Start accepts. Automaton has 297 states and 380 transitions. Word has length 47 [2022-11-02 20:58:53,381 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:53,382 INFO L495 AbstractCegarLoop]: Abstraction has 297 states and 380 transitions. [2022-11-02 20:58:53,382 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-02 20:58:53,382 INFO L276 IsEmpty]: Start isEmpty. Operand 297 states and 380 transitions. [2022-11-02 20:58:53,383 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 76 [2022-11-02 20:58:53,383 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:53,383 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:53,384 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-02 20:58:53,384 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:53,384 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:53,384 INFO L85 PathProgramCache]: Analyzing trace with hash -949050969, now seen corresponding path program 1 times [2022-11-02 20:58:53,385 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:53,385 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1509020027] [2022-11-02 20:58:53,385 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:53,385 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:53,413 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:58:53,513 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:53,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,540 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:58:53,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,544 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:53,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,549 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-11-02 20:58:53,550 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,552 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 6 proven. 1 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-02 20:58:53,552 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:53,552 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1509020027] [2022-11-02 20:58:53,553 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1509020027] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:58:53,553 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [658656964] [2022-11-02 20:58:53,553 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:53,553 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:58:53,553 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:58:53,559 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:58:53,562 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-02 20:58:53,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:53,672 INFO L263 TraceCheckSpWp]: Trace formula consists of 418 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-02 20:58:53,678 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:58:53,869 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:53,870 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-02 20:58:54,013 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:58:54,013 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [658656964] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-02 20:58:54,014 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-02 20:58:54,014 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 13 [2022-11-02 20:58:54,014 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1578793478] [2022-11-02 20:58:54,014 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-02 20:58:54,015 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-02 20:58:54,015 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:54,015 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-02 20:58:54,015 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=130, Unknown=0, NotChecked=0, Total=156 [2022-11-02 20:58:54,015 INFO L87 Difference]: Start difference. First operand 297 states and 380 transitions. Second operand has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-02 20:58:57,102 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:58:57,102 INFO L93 Difference]: Finished difference Result 1351 states and 1825 transitions. [2022-11-02 20:58:57,102 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 101 states. [2022-11-02 20:58:57,102 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) Word has length 75 [2022-11-02 20:58:57,104 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:58:57,111 INFO L225 Difference]: With dead ends: 1351 [2022-11-02 20:58:57,112 INFO L226 Difference]: Without dead ends: 1061 [2022-11-02 20:58:57,116 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 289 GetRequests, 180 SyntacticMatches, 6 SemanticMatches, 103 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4125 ImplicationChecksByTransitivity, 1.5s TimeCoverageRelationStatistics Valid=1749, Invalid=9171, Unknown=0, NotChecked=0, Total=10920 [2022-11-02 20:58:57,117 INFO L413 NwaCegarLoop]: 188 mSDtfsCounter, 868 mSDsluCounter, 974 mSDsCounter, 0 mSdLazyCounter, 1661 mSolverCounterSat, 406 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 874 SdHoareTripleChecker+Valid, 1162 SdHoareTripleChecker+Invalid, 2067 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 406 IncrementalHoareTripleChecker+Valid, 1661 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.5s IncrementalHoareTripleChecker+Time [2022-11-02 20:58:57,118 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [874 Valid, 1162 Invalid, 2067 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [406 Valid, 1661 Invalid, 0 Unknown, 0 Unchecked, 1.5s Time] [2022-11-02 20:58:57,119 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1061 states. [2022-11-02 20:58:57,206 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1061 to 836. [2022-11-02 20:58:57,207 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 836 states, 638 states have (on average 1.206896551724138) internal successors, (770), 680 states have internal predecessors, (770), 91 states have call successors, (91), 82 states have call predecessors, (91), 106 states have return successors, (222), 96 states have call predecessors, (222), 91 states have call successors, (222) [2022-11-02 20:58:57,211 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 836 states to 836 states and 1083 transitions. [2022-11-02 20:58:57,212 INFO L78 Accepts]: Start accepts. Automaton has 836 states and 1083 transitions. Word has length 75 [2022-11-02 20:58:57,212 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:58:57,212 INFO L495 AbstractCegarLoop]: Abstraction has 836 states and 1083 transitions. [2022-11-02 20:58:57,213 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-02 20:58:57,213 INFO L276 IsEmpty]: Start isEmpty. Operand 836 states and 1083 transitions. [2022-11-02 20:58:57,215 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 122 [2022-11-02 20:58:57,215 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:58:57,216 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:58:57,250 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-02 20:58:57,441 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:58:57,442 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:58:57,442 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:58:57,442 INFO L85 PathProgramCache]: Analyzing trace with hash -1084284902, now seen corresponding path program 1 times [2022-11-02 20:58:57,443 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:58:57,443 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1068773562] [2022-11-02 20:58:57,443 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:57,443 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:58:57,467 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,552 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:58:57,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,561 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:58:57,563 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,573 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:58:57,574 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,576 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:57,578 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,580 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-02 20:58:57,582 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,587 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:58:57,588 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:58:57,591 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,592 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:58:57,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,602 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 95 [2022-11-02 20:58:57,603 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,604 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 110 [2022-11-02 20:58:57,604 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,607 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 54 trivial. 0 not checked. [2022-11-02 20:58:57,607 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:58:57,607 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1068773562] [2022-11-02 20:58:57,608 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1068773562] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:58:57,608 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1189481381] [2022-11-02 20:58:57,608 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:58:57,608 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:58:57,608 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:58:57,610 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:58:57,633 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-02 20:58:57,737 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:58:57,739 INFO L263 TraceCheckSpWp]: Trace formula consists of 536 conjuncts, 11 conjunts are in the unsatisfiable core [2022-11-02 20:58:57,743 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:58:58,073 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 51 proven. 11 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-02 20:58:58,078 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-02 20:58:58,414 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 49 proven. 11 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-02 20:58:58,415 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1189481381] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-02 20:58:58,415 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-02 20:58:58,415 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 9, 9] total 21 [2022-11-02 20:58:58,415 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1642668028] [2022-11-02 20:58:58,416 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-02 20:58:58,417 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 21 states [2022-11-02 20:58:58,417 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:58:58,418 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 21 interpolants. [2022-11-02 20:58:58,418 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=69, Invalid=351, Unknown=0, NotChecked=0, Total=420 [2022-11-02 20:58:58,419 INFO L87 Difference]: Start difference. First operand 836 states and 1083 transitions. Second operand has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) [2022-11-02 20:59:01,888 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:59:01,888 INFO L93 Difference]: Finished difference Result 2384 states and 3309 transitions. [2022-11-02 20:59:01,889 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 70 states. [2022-11-02 20:59:01,889 INFO L78 Accepts]: Start accepts. Automaton has has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) Word has length 121 [2022-11-02 20:59:01,889 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:59:01,897 INFO L225 Difference]: With dead ends: 2384 [2022-11-02 20:59:01,897 INFO L226 Difference]: Without dead ends: 1647 [2022-11-02 20:59:01,906 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 367 GetRequests, 284 SyntacticMatches, 1 SemanticMatches, 82 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1861 ImplicationChecksByTransitivity, 1.5s TimeCoverageRelationStatistics Valid=1289, Invalid=5683, Unknown=0, NotChecked=0, Total=6972 [2022-11-02 20:59:01,907 INFO L413 NwaCegarLoop]: 242 mSDtfsCounter, 1146 mSDsluCounter, 548 mSDsCounter, 0 mSdLazyCounter, 2478 mSolverCounterSat, 663 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1152 SdHoareTripleChecker+Valid, 790 SdHoareTripleChecker+Invalid, 3141 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 663 IncrementalHoareTripleChecker+Valid, 2478 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.9s IncrementalHoareTripleChecker+Time [2022-11-02 20:59:01,907 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1152 Valid, 790 Invalid, 3141 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [663 Valid, 2478 Invalid, 0 Unknown, 0 Unchecked, 1.9s Time] [2022-11-02 20:59:01,909 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1647 states. [2022-11-02 20:59:02,052 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1647 to 1331. [2022-11-02 20:59:02,054 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1331 states, 1004 states have (on average 1.198207171314741) internal successors, (1203), 1061 states have internal predecessors, (1203), 152 states have call successors, (152), 142 states have call predecessors, (152), 174 states have return successors, (343), 158 states have call predecessors, (343), 152 states have call successors, (343) [2022-11-02 20:59:02,062 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1331 states to 1331 states and 1698 transitions. [2022-11-02 20:59:02,062 INFO L78 Accepts]: Start accepts. Automaton has 1331 states and 1698 transitions. Word has length 121 [2022-11-02 20:59:02,063 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:59:02,063 INFO L495 AbstractCegarLoop]: Abstraction has 1331 states and 1698 transitions. [2022-11-02 20:59:02,064 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) [2022-11-02 20:59:02,064 INFO L276 IsEmpty]: Start isEmpty. Operand 1331 states and 1698 transitions. [2022-11-02 20:59:02,076 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2022-11-02 20:59:02,076 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:59:02,077 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:59:02,115 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-02 20:59:02,289 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-02 20:59:02,290 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:59:02,290 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:59:02,290 INFO L85 PathProgramCache]: Analyzing trace with hash -1154537432, now seen corresponding path program 1 times [2022-11-02 20:59:02,290 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:59:02,290 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [337266274] [2022-11-02 20:59:02,290 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:59:02,291 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:59:02,307 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,402 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:59:02,403 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,411 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:59:02,413 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,421 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:59:02,422 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,424 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:59:02,425 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,427 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-02 20:59:02,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,488 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:59:02,491 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,543 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:59:02,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,547 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:59:02,547 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-11-02 20:59:02,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,557 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:59:02,558 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,560 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:59:02,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,561 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 41 trivial. 0 not checked. [2022-11-02 20:59:02,561 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:59:02,561 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [337266274] [2022-11-02 20:59:02,562 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [337266274] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:59:02,562 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [452707662] [2022-11-02 20:59:02,562 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:59:02,562 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:59:02,562 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:59:02,563 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:59:02,588 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-02 20:59:02,698 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:59:02,700 INFO L263 TraceCheckSpWp]: Trace formula consists of 563 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-02 20:59:02,703 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:59:02,744 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 62 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-11-02 20:59:02,744 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-02 20:59:02,745 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [452707662] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:59:02,745 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-02 20:59:02,745 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [10] total 12 [2022-11-02 20:59:02,745 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1406755677] [2022-11-02 20:59:02,745 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:59:02,746 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:59:02,746 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:59:02,746 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:59:02,746 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=25, Invalid=107, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:59:02,746 INFO L87 Difference]: Start difference. First operand 1331 states and 1698 transitions. Second operand has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-02 20:59:02,825 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:59:02,825 INFO L93 Difference]: Finished difference Result 1762 states and 2225 transitions. [2022-11-02 20:59:02,825 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:59:02,826 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 131 [2022-11-02 20:59:02,826 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:59:02,826 INFO L225 Difference]: With dead ends: 1762 [2022-11-02 20:59:02,827 INFO L226 Difference]: Without dead ends: 0 [2022-11-02 20:59:02,830 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 170 GetRequests, 158 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=38, Invalid=144, Unknown=0, NotChecked=0, Total=182 [2022-11-02 20:59:02,831 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 9 mSDsluCounter, 274 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 371 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:59:02,831 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 371 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:59:02,832 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-02 20:59:02,832 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-02 20:59:02,832 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:59:02,832 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-02 20:59:02,832 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 131 [2022-11-02 20:59:02,832 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:59:02,832 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-02 20:59:02,833 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-02 20:59:02,833 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-02 20:59:02,833 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-02 20:59:02,835 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-02 20:59:02,878 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-02 20:59:03,050 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-02 20:59:03,051 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-02 20:59:07,549 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 615 622) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-02 20:59:07,549 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 615 622) no Hoare annotation was computed. [2022-11-02 20:59:07,550 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 615 622) no Hoare annotation was computed. [2022-11-02 20:59:07,550 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 522 528) no Hoare annotation was computed. [2022-11-02 20:59:07,550 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 522 528) the Hoare annotation is: true [2022-11-02 20:59:07,550 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 792 803) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0))) (and (or (not (= ~waterLevel~0 1)) (not (= ~pumpRunning~0 0)) .cse0 .cse1) (or .cse0 .cse1 (< ~waterLevel~0 2)))) [2022-11-02 20:59:07,550 INFO L899 garLoopResultBuilder]: For program point L796-1(lines 792 803) no Hoare annotation was computed. [2022-11-02 20:59:07,550 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 792 803) no Hoare annotation was computed. [2022-11-02 20:59:07,551 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 896 925) no Hoare annotation was computed. [2022-11-02 20:59:07,551 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 896 925) the Hoare annotation is: true [2022-11-02 20:59:07,551 INFO L902 garLoopResultBuilder]: At program point L921(lines 896 925) the Hoare annotation is: true [2022-11-02 20:59:07,551 INFO L899 garLoopResultBuilder]: For program point L917(line 917) no Hoare annotation was computed. [2022-11-02 20:59:07,551 INFO L899 garLoopResultBuilder]: For program point L910(lines 910 914) no Hoare annotation was computed. [2022-11-02 20:59:07,551 INFO L902 garLoopResultBuilder]: At program point L910-1(lines 910 914) the Hoare annotation is: true [2022-11-02 20:59:07,551 INFO L899 garLoopResultBuilder]: For program point L907(line 907) no Hoare annotation was computed. [2022-11-02 20:59:07,552 INFO L902 garLoopResultBuilder]: At program point L906-2(lines 906 920) the Hoare annotation is: true [2022-11-02 20:59:07,552 INFO L902 garLoopResultBuilder]: At program point L902(line 902) the Hoare annotation is: true [2022-11-02 20:59:07,552 INFO L899 garLoopResultBuilder]: For program point L902-1(line 902) no Hoare annotation was computed. [2022-11-02 20:59:07,552 INFO L895 garLoopResultBuilder]: At program point L601(line 601) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-02 20:59:07,553 INFO L895 garLoopResultBuilder]: At program point L601-1(lines 582 606) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (<= 2 ~waterLevel~0)) (.cse4 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) (or .cse0 .cse2 (not (= |old(~waterLevel~0)| 1)) .cse1) (let ((.cse3 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse2 .cse3) .cse1 .cse4 (and .cse5 .cse3))) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse1 .cse5 .cse4 (not (= ~methaneLevelCritical~0 0))))) [2022-11-02 20:59:07,553 INFO L895 garLoopResultBuilder]: At program point L630(lines 623 633) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (and (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0))) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-02 20:59:07,553 INFO L899 garLoopResultBuilder]: For program point L502-1(lines 501 520) no Hoare annotation was computed. [2022-11-02 20:59:07,553 INFO L895 garLoopResultBuilder]: At program point L841(lines 836 844) the Hoare annotation is: (let ((.cse4 (<= 2 ~waterLevel~0)) (.cse3 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (< |old(~waterLevel~0)| 2)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse6 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse3)) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse1 (and .cse4 .cse3) .cse2 (not (= ~methaneLevelCritical~0 0))) (let ((.cse5 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse4 .cse5 .cse3) .cse1 .cse2 (and .cse6 .cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse6 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-02 20:59:07,554 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 498 521) no Hoare annotation was computed. [2022-11-02 20:59:07,554 INFO L895 garLoopResultBuilder]: At program point L639(lines 634 642) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-02 20:59:07,554 INFO L899 garLoopResultBuilder]: For program point L590(lines 590 598) no Hoare annotation was computed. [2022-11-02 20:59:07,554 INFO L899 garLoopResultBuilder]: For program point L586(lines 586 603) no Hoare annotation was computed. [2022-11-02 20:59:07,554 INFO L895 garLoopResultBuilder]: At program point L809(lines 804 812) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-02 20:59:07,555 INFO L899 garLoopResultBuilder]: For program point L772(lines 772 776) no Hoare annotation was computed. [2022-11-02 20:59:07,555 INFO L895 garLoopResultBuilder]: At program point L772-2(lines 768 779) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-02 20:59:07,555 INFO L899 garLoopResultBuilder]: For program point L760(line 760) no Hoare annotation was computed. [2022-11-02 20:59:07,555 INFO L899 garLoopResultBuilder]: For program point L509-1(lines 509 515) no Hoare annotation was computed. [2022-11-02 20:59:07,555 INFO L895 garLoopResultBuilder]: At program point L761(lines 756 763) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-02 20:59:07,556 INFO L895 garLoopResultBuilder]: At program point L596(line 596) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (and (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_processEnvironment_~tmp~6#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse1))) [2022-11-02 20:59:07,556 INFO L899 garLoopResultBuilder]: For program point L881(lines 881 887) no Hoare annotation was computed. [2022-11-02 20:59:07,556 INFO L895 garLoopResultBuilder]: At program point L592(line 592) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2022-11-02 20:59:07,556 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 498 521) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-02 20:59:07,556 INFO L899 garLoopResultBuilder]: For program point L877(lines 877 890) no Hoare annotation was computed. [2022-11-02 20:59:07,557 INFO L895 garLoopResultBuilder]: At program point L877-1(lines 869 893) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= ~pumpRunning~0 0)) (.cse3 (not (= 1 ~systemActive~0))) (.cse4 (< |old(~waterLevel~0)| 2)) (.cse1 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|))) (and (or .cse0 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1 .cse2) .cse3 .cse4) (let ((.cse5 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and (<= 2 ~waterLevel~0) .cse5 .cse1 .cse2) .cse3 (and .cse6 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|) .cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)) .cse4)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1| 1) .cse6 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse3 .cse4 (and (not (< ~waterLevel~0 2)) .cse1 .cse2) (not (= ~methaneLevelCritical~0 0))))) [2022-11-02 20:59:07,557 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 498 521) no Hoare annotation was computed. [2022-11-02 20:59:07,557 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 760) no Hoare annotation was computed. [2022-11-02 20:59:07,557 INFO L895 garLoopResultBuilder]: At program point L473(lines 430 475) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L440(lines 440 446) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L440-1(lines 440 446) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L977(lines 977 984) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L977-2(lines 977 984) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-02 20:59:07,558 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-02 20:59:07,559 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-02 20:59:07,559 INFO L902 garLoopResultBuilder]: At program point L986(lines 967 989) the Hoare annotation is: true [2022-11-02 20:59:07,559 INFO L899 garLoopResultBuilder]: For program point L466(lines 466 470) no Hoare annotation was computed. [2022-11-02 20:59:07,559 INFO L895 garLoopResultBuilder]: At program point L466-2(lines 460 471) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-02 20:59:07,559 INFO L895 garLoopResultBuilder]: At program point L751(lines 746 754) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:59:07,559 INFO L895 garLoopResultBuilder]: At program point L743(lines 739 745) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:59:07,560 INFO L899 garLoopResultBuilder]: For program point L450(lines 450 456) no Hoare annotation was computed. [2022-11-02 20:59:07,560 INFO L899 garLoopResultBuilder]: For program point L450-1(lines 450 456) no Hoare annotation was computed. [2022-11-02 20:59:07,560 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-02 20:59:07,560 INFO L902 garLoopResultBuilder]: At program point L479(lines 420 483) the Hoare annotation is: true [2022-11-02 20:59:07,560 INFO L895 garLoopResultBuilder]: At program point L954(lines 950 956) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~10#1| 1)) [2022-11-02 20:59:07,561 INFO L895 garLoopResultBuilder]: At program point L442(line 442) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-02 20:59:07,561 INFO L895 garLoopResultBuilder]: At program point L736(lines 732 738) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:59:07,561 INFO L895 garLoopResultBuilder]: At program point L476(lines 429 477) the Hoare annotation is: false [2022-11-02 20:59:07,561 INFO L899 garLoopResultBuilder]: For program point L431(lines 430 475) no Hoare annotation was computed. [2022-11-02 20:59:07,561 INFO L899 garLoopResultBuilder]: For program point L460(lines 460 471) no Hoare annotation was computed. [2022-11-02 20:59:07,561 INFO L895 garLoopResultBuilder]: At program point L452(line 452) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-02 20:59:07,562 INFO L902 garLoopResultBuilder]: At program point L964(lines 957 966) the Hoare annotation is: true [2022-11-02 20:59:07,562 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 530 554) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-02 20:59:07,562 INFO L895 garLoopResultBuilder]: At program point L694(lines 679 697) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~7#1| 0)) .cse0 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (and .cse0 (<= 2 ~waterLevel~0)))) [2022-11-02 20:59:07,562 INFO L899 garLoopResultBuilder]: For program point L849(lines 849 855) no Hoare annotation was computed. [2022-11-02 20:59:07,562 INFO L899 garLoopResultBuilder]: For program point L688(lines 688 692) no Hoare annotation was computed. [2022-11-02 20:59:07,562 INFO L899 garLoopResultBuilder]: For program point L688-2(lines 688 692) no Hoare annotation was computed. [2022-11-02 20:59:07,563 INFO L895 garLoopResultBuilder]: At program point L612(lines 607 614) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-11-02 20:59:07,563 INFO L895 garLoopResultBuilder]: At program point L544(line 544) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_~tmp~4#1| 0))) [2022-11-02 20:59:07,563 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 530 554) no Hoare annotation was computed. [2022-11-02 20:59:07,563 INFO L899 garLoopResultBuilder]: For program point L538(lines 538 546) no Hoare annotation was computed. [2022-11-02 20:59:07,563 INFO L899 garLoopResultBuilder]: For program point L534(lines 534 551) no Hoare annotation was computed. [2022-11-02 20:59:07,564 INFO L895 garLoopResultBuilder]: At program point L854(lines 845 858) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 .cse2 (and .cse1 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))))) [2022-11-02 20:59:07,564 INFO L895 garLoopResultBuilder]: At program point L549(line 549) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-02 20:59:07,564 INFO L899 garLoopResultBuilder]: For program point L549-1(lines 530 554) no Hoare annotation was computed. [2022-11-02 20:59:07,564 INFO L899 garLoopResultBuilder]: For program point L784-1(lines 780 791) no Hoare annotation was computed. [2022-11-02 20:59:07,564 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 780 791) no Hoare annotation was computed. [2022-11-02 20:59:07,564 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 780 791) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-02 20:59:07,565 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 556 580) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-02 20:59:07,565 INFO L895 garLoopResultBuilder]: At program point L570(line 570) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-02 20:59:07,565 INFO L895 garLoopResultBuilder]: At program point L566(line 566) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~5#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))))) [2022-11-02 20:59:07,565 INFO L899 garLoopResultBuilder]: For program point L564(lines 564 572) no Hoare annotation was computed. [2022-11-02 20:59:07,565 INFO L899 garLoopResultBuilder]: For program point L560(lines 560 577) no Hoare annotation was computed. [2022-11-02 20:59:07,566 INFO L895 garLoopResultBuilder]: At program point L713(lines 698 716) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-02 20:59:07,566 INFO L899 garLoopResultBuilder]: For program point L707(lines 707 711) no Hoare annotation was computed. [2022-11-02 20:59:07,566 INFO L899 garLoopResultBuilder]: For program point L707-2(lines 707 711) no Hoare annotation was computed. [2022-11-02 20:59:07,566 INFO L895 garLoopResultBuilder]: At program point L864(lines 859 867) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-02 20:59:07,566 INFO L895 garLoopResultBuilder]: At program point L575(line 575) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) [2022-11-02 20:59:07,567 INFO L899 garLoopResultBuilder]: For program point L575-1(lines 556 580) no Hoare annotation was computed. [2022-11-02 20:59:07,567 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 556 580) no Hoare annotation was computed. [2022-11-02 20:59:07,570 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:59:07,572 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-02 20:59:07,602 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 02.11 08:59:07 BoogieIcfgContainer [2022-11-02 20:59:07,603 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-02 20:59:07,620 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-02 20:59:07,620 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-02 20:59:07,620 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-02 20:59:07,621 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:58:49" (3/4) ... [2022-11-02 20:59:07,624 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-02 20:59:07,630 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-02 20:59:07,630 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-02 20:59:07,630 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-02 20:59:07,630 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-02 20:59:07,631 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-02 20:59:07,631 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:59:07,631 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-02 20:59:07,631 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-11-02 20:59:07,638 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-02 20:59:07,642 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-02 20:59:07,642 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-02 20:59:07,643 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-02 20:59:07,643 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-02 20:59:07,643 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:59:07,644 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:59:07,667 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-11-02 20:59:07,667 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == 1 [2022-11-02 20:59:07,668 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((2 <= waterLevel && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == 1) || (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) [2022-11-02 20:59:07,668 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-02 20:59:07,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive))) && ((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || 2 <= waterLevel) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) [2022-11-02 20:59:07,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || (2 <= waterLevel && 2 <= \result)) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0))) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-11-02 20:59:07,670 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || \result == 0)) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-02 20:59:07,670 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp)) || !(1 == systemActive)) || \old(waterLevel) < 2) && ((((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) && 2 <= tmp) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || \old(waterLevel) < 2)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((!(waterLevel < 2) && 2 <= \result) && 2 <= tmp)) || !(methaneLevelCritical == 0)) [2022-11-02 20:59:07,670 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || (\result == 0 && \result == 0))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-02 20:59:07,670 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-02 20:59:07,670 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-02 20:59:07,671 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) [2022-11-02 20:59:07,671 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((pumpRunning == \old(pumpRunning) && tmp == 0) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-02 20:59:07,671 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-02 20:59:07,671 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel) [2022-11-02 20:59:07,672 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) [2022-11-02 20:59:07,695 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/witness.graphml [2022-11-02 20:59:07,696 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-02 20:59:07,696 INFO L158 Benchmark]: Toolchain (without parser) took 19494.39ms. Allocated memory was 119.5MB in the beginning and 255.9MB in the end (delta: 136.3MB). Free memory was 84.8MB in the beginning and 84.9MB in the end (delta: -89.6kB). Peak memory consumption was 135.3MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,697 INFO L158 Benchmark]: CDTParser took 0.23ms. Allocated memory is still 79.7MB. Free memory was 52.2MB in the beginning and 52.2MB in the end (delta: 28.5kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-02 20:59:07,697 INFO L158 Benchmark]: CACSL2BoogieTranslator took 502.82ms. Allocated memory is still 119.5MB. Free memory was 84.6MB in the beginning and 88.1MB in the end (delta: -3.5MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,697 INFO L158 Benchmark]: Boogie Procedure Inliner took 46.81ms. Allocated memory is still 119.5MB. Free memory was 87.7MB in the beginning and 85.0MB in the end (delta: 2.7MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,698 INFO L158 Benchmark]: Boogie Preprocessor took 26.68ms. Allocated memory is still 119.5MB. Free memory was 85.0MB in the beginning and 83.5MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-02 20:59:07,698 INFO L158 Benchmark]: RCFGBuilder took 642.23ms. Allocated memory is still 119.5MB. Free memory was 83.5MB in the beginning and 63.5MB in the end (delta: 20.0MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,698 INFO L158 Benchmark]: TraceAbstraction took 18177.03ms. Allocated memory was 119.5MB in the beginning and 255.9MB in the end (delta: 136.3MB). Free memory was 62.9MB in the beginning and 91.1MB in the end (delta: -28.2MB). Peak memory consumption was 126.2MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,699 INFO L158 Benchmark]: Witness Printer took 75.98ms. Allocated memory is still 255.9MB. Free memory was 91.1MB in the beginning and 84.9MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-02 20:59:07,700 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.23ms. Allocated memory is still 79.7MB. Free memory was 52.2MB in the beginning and 52.2MB in the end (delta: 28.5kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 502.82ms. Allocated memory is still 119.5MB. Free memory was 84.6MB in the beginning and 88.1MB in the end (delta: -3.5MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 46.81ms. Allocated memory is still 119.5MB. Free memory was 87.7MB in the beginning and 85.0MB in the end (delta: 2.7MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 26.68ms. Allocated memory is still 119.5MB. Free memory was 85.0MB in the beginning and 83.5MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 642.23ms. Allocated memory is still 119.5MB. Free memory was 83.5MB in the beginning and 63.5MB in the end (delta: 20.0MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * TraceAbstraction took 18177.03ms. Allocated memory was 119.5MB in the beginning and 255.9MB in the end (delta: 136.3MB). Free memory was 62.9MB in the beginning and 91.1MB in the end (delta: -28.2MB). Peak memory consumption was 126.2MB. Max. memory is 16.1GB. * Witness Printer took 75.98ms. Allocated memory is still 255.9MB. Free memory was 91.1MB in the beginning and 84.9MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 760]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 95 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 18.1s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 8.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.5s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3017 SdHoareTripleChecker+Valid, 4.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2988 mSDsluCounter, 5045 SdHoareTripleChecker+Invalid, 3.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3534 mSDsCounter, 1323 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 5213 IncrementalHoareTripleChecker+Invalid, 6536 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1323 mSolverCounterUnsat, 1511 mSDtfsCounter, 5213 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 933 GetRequests, 670 SyntacticMatches, 10 SemanticMatches, 253 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6068 ImplicationChecksByTransitivity, 3.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1331occurred in iteration=11, InterpolantAutomatonStates: 237, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 12 MinimizatonAttempts, 608 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 1916 PreInvPairs, 2121 NumberOfFragments, 1214 HoareAnnotationTreeSize, 1916 FomulaSimplifications, 2459 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 45 FomulaSimplificationsInter, 16749 FormulaSimplificationTreeSizeReductionInter, 3.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 2.8s InterpolantComputationTime, 971 NumberOfCodeBlocks, 971 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1150 ConstructedInterpolants, 0 QuantifiedInterpolants, 2193 SizeOfPredicates, 10 NumberOfNonLiveVariables, 1517 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 17 InterpolantComputations, 10 PerfectInterpolantSequences, 381/420 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 634]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 859]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 582]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive))) && ((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || 2 <= waterLevel) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 732]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 896]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 869]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp)) || !(1 == systemActive)) || \old(waterLevel) < 2) && ((((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) && 2 <= tmp) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || \old(waterLevel) < 2)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((!(waterLevel < 2) && 2 <= \result) && 2 <= tmp)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 746]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 957]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 804]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || \result == 0)) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == 1) || (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) - InvariantResult [Line: 623]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || (\result == 0 && \result == 0))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 739]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 429]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 950]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == 1 - InvariantResult [Line: 967]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 698]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((pumpRunning == \old(pumpRunning) && tmp == 0) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 679]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel) - InvariantResult [Line: 768]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 607]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) - InvariantResult [Line: 845]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) - InvariantResult [Line: 836]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || (2 <= waterLevel && 2 <= \result)) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0))) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 756]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 420]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-02 20:59:07,758 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_aea0e273-8968-4c79-b7cc-b77ad1213837/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE