./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 7c7779f94f1738e754b88f9a8a8e36de7065a4e94578f4135106bd0ff9ddb13d --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-02 20:51:13,741 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-02 20:51:13,743 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-02 20:51:13,782 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-02 20:51:13,782 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-02 20:51:13,788 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-02 20:51:13,790 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-02 20:51:13,794 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-02 20:51:13,798 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-02 20:51:13,801 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-02 20:51:13,802 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-02 20:51:13,805 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-02 20:51:13,805 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-02 20:51:13,812 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-02 20:51:13,814 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-02 20:51:13,816 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-02 20:51:13,818 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-02 20:51:13,819 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-02 20:51:13,821 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-02 20:51:13,822 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-02 20:51:13,829 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-02 20:51:13,831 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-02 20:51:13,832 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-02 20:51:13,834 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-02 20:51:13,838 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-02 20:51:13,843 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-02 20:51:13,843 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-02 20:51:13,844 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-02 20:51:13,846 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-02 20:51:13,847 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-02 20:51:13,847 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-02 20:51:13,848 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-02 20:51:13,850 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-02 20:51:13,852 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-02 20:51:13,853 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-02 20:51:13,853 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-02 20:51:13,854 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-02 20:51:13,854 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-02 20:51:13,855 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-02 20:51:13,855 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-02 20:51:13,856 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-02 20:51:13,857 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-02 20:51:13,898 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-02 20:51:13,898 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-02 20:51:13,899 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-02 20:51:13,899 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-02 20:51:13,900 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-02 20:51:13,901 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-02 20:51:13,901 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-02 20:51:13,902 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-02 20:51:13,902 INFO L138 SettingsManager]: * Use SBE=true [2022-11-02 20:51:13,902 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-02 20:51:13,903 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-02 20:51:13,904 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-02 20:51:13,904 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-02 20:51:13,904 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-02 20:51:13,904 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-02 20:51:13,905 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-02 20:51:13,905 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-02 20:51:13,905 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-02 20:51:13,905 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-02 20:51:13,905 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-02 20:51:13,906 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-02 20:51:13,906 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-02 20:51:13,906 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-02 20:51:13,906 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-02 20:51:13,907 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:51:13,907 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-02 20:51:13,907 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-02 20:51:13,907 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-02 20:51:13,908 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-02 20:51:13,908 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-02 20:51:13,908 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-02 20:51:13,908 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-02 20:51:13,909 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-02 20:51:13,909 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 7c7779f94f1738e754b88f9a8a8e36de7065a4e94578f4135106bd0ff9ddb13d [2022-11-02 20:51:14,267 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-02 20:51:14,304 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-02 20:51:14,307 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-02 20:51:14,309 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-02 20:51:14,310 INFO L275 PluginConnector]: CDTParser initialized [2022-11-02 20:51:14,311 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c [2022-11-02 20:51:14,384 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/data/b0ae54ab9/07d75491395049fcbfda8b4a0aa6bc56/FLAG9564b35ef [2022-11-02 20:51:14,907 INFO L306 CDTParser]: Found 1 translation units. [2022-11-02 20:51:14,908 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c [2022-11-02 20:51:14,919 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/data/b0ae54ab9/07d75491395049fcbfda8b4a0aa6bc56/FLAG9564b35ef [2022-11-02 20:51:15,200 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/data/b0ae54ab9/07d75491395049fcbfda8b4a0aa6bc56 [2022-11-02 20:51:15,202 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-02 20:51:15,204 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-02 20:51:15,206 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-02 20:51:15,206 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-02 20:51:15,212 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-02 20:51:15,213 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,215 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@42261970 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15, skipping insertion in model container [2022-11-02 20:51:15,217 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,226 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-02 20:51:15,283 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-02 20:51:15,721 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c[15018,15031] [2022-11-02 20:51:15,767 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:51:15,787 INFO L203 MainTranslator]: Completed pre-run [2022-11-02 20:51:15,867 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c[15018,15031] [2022-11-02 20:51:15,879 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:51:15,903 INFO L208 MainTranslator]: Completed translation [2022-11-02 20:51:15,903 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15 WrapperNode [2022-11-02 20:51:15,904 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-02 20:51:15,905 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-02 20:51:15,905 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-02 20:51:15,905 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-02 20:51:15,913 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,937 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,972 INFO L138 Inliner]: procedures = 58, calls = 162, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 294 [2022-11-02 20:51:15,972 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-02 20:51:15,973 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-02 20:51:15,973 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-02 20:51:15,974 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-02 20:51:15,984 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,984 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,987 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,988 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,994 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:15,999 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:16,001 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:16,003 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:16,005 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-02 20:51:16,006 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-02 20:51:16,007 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-02 20:51:16,007 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-02 20:51:16,008 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (1/1) ... [2022-11-02 20:51:16,014 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:51:16,036 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:51:16,049 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-02 20:51:16,057 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-02 20:51:16,094 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-02 20:51:16,094 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-02 20:51:16,094 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-02 20:51:16,094 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-02 20:51:16,095 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-02 20:51:16,095 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-02 20:51:16,095 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-02 20:51:16,097 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:51:16,097 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:51:16,098 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-02 20:51:16,098 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-02 20:51:16,098 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2022-11-02 20:51:16,098 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2022-11-02 20:51:16,098 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2022-11-02 20:51:16,099 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2022-11-02 20:51:16,099 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-02 20:51:16,099 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-02 20:51:16,099 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-02 20:51:16,099 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-02 20:51:16,099 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-02 20:51:16,100 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-02 20:51:16,100 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-02 20:51:16,190 INFO L235 CfgBuilder]: Building ICFG [2022-11-02 20:51:16,192 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-02 20:51:16,660 INFO L276 CfgBuilder]: Performing block encoding [2022-11-02 20:51:16,675 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-02 20:51:16,675 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-02 20:51:16,679 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:51:16 BoogieIcfgContainer [2022-11-02 20:51:16,679 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-02 20:51:16,682 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-02 20:51:16,683 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-02 20:51:16,688 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-02 20:51:16,688 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 02.11 08:51:15" (1/3) ... [2022-11-02 20:51:16,689 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@126ff6ab and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:51:16, skipping insertion in model container [2022-11-02 20:51:16,690 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:51:15" (2/3) ... [2022-11-02 20:51:16,690 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@126ff6ab and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:51:16, skipping insertion in model container [2022-11-02 20:51:16,690 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:51:16" (3/3) ... [2022-11-02 20:51:16,692 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product63.cil.c [2022-11-02 20:51:16,711 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-02 20:51:16,712 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-02 20:51:16,776 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-02 20:51:16,788 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@25217a85, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-02 20:51:16,790 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-02 20:51:16,796 INFO L276 IsEmpty]: Start isEmpty. Operand has 107 states, 79 states have (on average 1.379746835443038) internal successors, (109), 90 states have internal predecessors, (109), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2022-11-02 20:51:16,808 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-02 20:51:16,808 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:16,809 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:16,810 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:16,818 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:16,818 INFO L85 PathProgramCache]: Analyzing trace with hash 1070951928, now seen corresponding path program 1 times [2022-11-02 20:51:16,828 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:16,830 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [156738588] [2022-11-02 20:51:16,830 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:16,830 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:16,992 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:17,086 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:17,087 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:17,087 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [156738588] [2022-11-02 20:51:17,088 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [156738588] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:17,088 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:17,088 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-02 20:51:17,090 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1924224883] [2022-11-02 20:51:17,090 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:17,093 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-02 20:51:17,094 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:17,123 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-02 20:51:17,123 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:51:17,126 INFO L87 Difference]: Start difference. First operand has 107 states, 79 states have (on average 1.379746835443038) internal successors, (109), 90 states have internal predecessors, (109), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:17,162 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:17,163 INFO L93 Difference]: Finished difference Result 206 states and 281 transitions. [2022-11-02 20:51:17,164 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-02 20:51:17,165 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-02 20:51:17,166 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:17,175 INFO L225 Difference]: With dead ends: 206 [2022-11-02 20:51:17,176 INFO L226 Difference]: Without dead ends: 98 [2022-11-02 20:51:17,179 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:51:17,183 INFO L413 NwaCegarLoop]: 137 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 137 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:17,184 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 137 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:51:17,203 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 98 states. [2022-11-02 20:51:17,239 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 98 to 98. [2022-11-02 20:51:17,241 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 98 states, 72 states have (on average 1.3194444444444444) internal successors, (95), 82 states have internal predecessors, (95), 17 states have call successors, (17), 9 states have call predecessors, (17), 8 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2022-11-02 20:51:17,248 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 98 states to 98 states and 128 transitions. [2022-11-02 20:51:17,253 INFO L78 Accepts]: Start accepts. Automaton has 98 states and 128 transitions. Word has length 19 [2022-11-02 20:51:17,254 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:17,255 INFO L495 AbstractCegarLoop]: Abstraction has 98 states and 128 transitions. [2022-11-02 20:51:17,256 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:17,256 INFO L276 IsEmpty]: Start isEmpty. Operand 98 states and 128 transitions. [2022-11-02 20:51:17,258 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-02 20:51:17,259 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:17,259 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:17,260 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-02 20:51:17,260 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:17,261 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:17,262 INFO L85 PathProgramCache]: Analyzing trace with hash -630554312, now seen corresponding path program 1 times [2022-11-02 20:51:17,262 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:17,263 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2009610247] [2022-11-02 20:51:17,263 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:17,263 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:17,314 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:17,498 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:17,498 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:17,498 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2009610247] [2022-11-02 20:51:17,499 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2009610247] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:17,499 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:17,499 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-02 20:51:17,500 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [191853267] [2022-11-02 20:51:17,500 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:17,501 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-02 20:51:17,502 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:17,502 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-02 20:51:17,503 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:51:17,503 INFO L87 Difference]: Start difference. First operand 98 states and 128 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:17,526 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:17,526 INFO L93 Difference]: Finished difference Result 158 states and 206 transitions. [2022-11-02 20:51:17,527 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-02 20:51:17,527 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-02 20:51:17,527 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:17,529 INFO L225 Difference]: With dead ends: 158 [2022-11-02 20:51:17,529 INFO L226 Difference]: Without dead ends: 89 [2022-11-02 20:51:17,530 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:51:17,532 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 16 mSDsluCounter, 94 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:17,533 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 209 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:51:17,534 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2022-11-02 20:51:17,543 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 89. [2022-11-02 20:51:17,544 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 89 states, 66 states have (on average 1.3333333333333333) internal successors, (88), 76 states have internal predecessors, (88), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-02 20:51:17,546 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 89 states to 89 states and 116 transitions. [2022-11-02 20:51:17,546 INFO L78 Accepts]: Start accepts. Automaton has 89 states and 116 transitions. Word has length 20 [2022-11-02 20:51:17,547 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:17,547 INFO L495 AbstractCegarLoop]: Abstraction has 89 states and 116 transitions. [2022-11-02 20:51:17,547 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:17,547 INFO L276 IsEmpty]: Start isEmpty. Operand 89 states and 116 transitions. [2022-11-02 20:51:17,548 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-02 20:51:17,549 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:17,549 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:17,549 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-02 20:51:17,549 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:17,550 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:17,550 INFO L85 PathProgramCache]: Analyzing trace with hash 735150912, now seen corresponding path program 1 times [2022-11-02 20:51:17,550 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:17,551 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1058936210] [2022-11-02 20:51:17,551 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:17,551 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:17,573 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:17,697 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:17,697 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:17,697 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1058936210] [2022-11-02 20:51:17,698 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1058936210] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:17,698 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:17,698 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:51:17,698 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1384311369] [2022-11-02 20:51:17,699 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:17,699 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:51:17,699 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:17,700 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:51:17,700 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:51:17,700 INFO L87 Difference]: Start difference. First operand 89 states and 116 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:17,985 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:17,986 INFO L93 Difference]: Finished difference Result 290 states and 385 transitions. [2022-11-02 20:51:17,986 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-02 20:51:17,987 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-11-02 20:51:17,988 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:17,991 INFO L225 Difference]: With dead ends: 290 [2022-11-02 20:51:17,994 INFO L226 Difference]: Without dead ends: 208 [2022-11-02 20:51:17,995 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-02 20:51:17,999 INFO L413 NwaCegarLoop]: 138 mSDtfsCounter, 310 mSDsluCounter, 342 mSDsCounter, 0 mSdLazyCounter, 127 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 310 SdHoareTripleChecker+Valid, 480 SdHoareTripleChecker+Invalid, 168 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 127 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:18,001 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [310 Valid, 480 Invalid, 168 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 127 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:51:18,003 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 208 states. [2022-11-02 20:51:18,033 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 208 to 202. [2022-11-02 20:51:18,034 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 202 states, 149 states have (on average 1.3624161073825503) internal successors, (203), 171 states have internal predecessors, (203), 32 states have call successors, (32), 20 states have call predecessors, (32), 20 states have return successors, (33), 20 states have call predecessors, (33), 32 states have call successors, (33) [2022-11-02 20:51:18,037 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 202 states to 202 states and 268 transitions. [2022-11-02 20:51:18,037 INFO L78 Accepts]: Start accepts. Automaton has 202 states and 268 transitions. Word has length 24 [2022-11-02 20:51:18,038 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:18,038 INFO L495 AbstractCegarLoop]: Abstraction has 202 states and 268 transitions. [2022-11-02 20:51:18,038 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:18,038 INFO L276 IsEmpty]: Start isEmpty. Operand 202 states and 268 transitions. [2022-11-02 20:51:18,040 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-02 20:51:18,040 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:18,040 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:18,040 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-02 20:51:18,041 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:18,041 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:18,041 INFO L85 PathProgramCache]: Analyzing trace with hash 769011574, now seen corresponding path program 1 times [2022-11-02 20:51:18,042 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:18,042 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [698808181] [2022-11-02 20:51:18,042 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:18,042 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:18,060 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:18,223 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:18,223 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:18,224 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [698808181] [2022-11-02 20:51:18,224 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [698808181] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:18,224 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:18,224 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-02 20:51:18,224 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1889040681] [2022-11-02 20:51:18,225 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:18,225 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:51:18,225 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:18,226 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:51:18,226 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:51:18,226 INFO L87 Difference]: Start difference. First operand 202 states and 268 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:18,342 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:18,342 INFO L93 Difference]: Finished difference Result 575 states and 793 transitions. [2022-11-02 20:51:18,342 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:51:18,343 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-11-02 20:51:18,343 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:18,347 INFO L225 Difference]: With dead ends: 575 [2022-11-02 20:51:18,347 INFO L226 Difference]: Without dead ends: 380 [2022-11-02 20:51:18,348 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:51:18,352 INFO L413 NwaCegarLoop]: 123 mSDtfsCounter, 87 mSDsluCounter, 349 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 87 SdHoareTripleChecker+Valid, 472 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:18,357 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [87 Valid, 472 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:51:18,360 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 380 states. [2022-11-02 20:51:18,445 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 380 to 380. [2022-11-02 20:51:18,448 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 380 states, 278 states have (on average 1.3381294964028776) internal successors, (372), 318 states have internal predecessors, (372), 64 states have call successors, (64), 40 states have call predecessors, (64), 37 states have return successors, (70), 37 states have call predecessors, (70), 64 states have call successors, (70) [2022-11-02 20:51:18,457 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 380 states to 380 states and 506 transitions. [2022-11-02 20:51:18,457 INFO L78 Accepts]: Start accepts. Automaton has 380 states and 506 transitions. Word has length 28 [2022-11-02 20:51:18,457 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:18,458 INFO L495 AbstractCegarLoop]: Abstraction has 380 states and 506 transitions. [2022-11-02 20:51:18,458 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:18,458 INFO L276 IsEmpty]: Start isEmpty. Operand 380 states and 506 transitions. [2022-11-02 20:51:18,467 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-11-02 20:51:18,468 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:18,468 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:18,468 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-02 20:51:18,469 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:18,469 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:18,469 INFO L85 PathProgramCache]: Analyzing trace with hash 1555028603, now seen corresponding path program 1 times [2022-11-02 20:51:18,470 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:18,470 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1767741753] [2022-11-02 20:51:18,470 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:18,470 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:18,504 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:18,615 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:18,615 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:18,616 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1767741753] [2022-11-02 20:51:18,616 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1767741753] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:18,616 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:18,617 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-02 20:51:18,618 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [366262396] [2022-11-02 20:51:18,618 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:18,619 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-02 20:51:18,619 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:18,620 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-02 20:51:18,621 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:51:18,622 INFO L87 Difference]: Start difference. First operand 380 states and 506 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:18,719 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:18,720 INFO L93 Difference]: Finished difference Result 870 states and 1181 transitions. [2022-11-02 20:51:18,720 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-02 20:51:18,720 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-11-02 20:51:18,721 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:18,727 INFO L225 Difference]: With dead ends: 870 [2022-11-02 20:51:18,728 INFO L226 Difference]: Without dead ends: 497 [2022-11-02 20:51:18,729 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:51:18,733 INFO L413 NwaCegarLoop]: 116 mSDtfsCounter, 67 mSDsluCounter, 73 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 189 SdHoareTripleChecker+Invalid, 23 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:18,741 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 189 Invalid, 23 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:51:18,743 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 497 states. [2022-11-02 20:51:18,793 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 497 to 486. [2022-11-02 20:51:18,794 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 486 states, 368 states have (on average 1.2771739130434783) internal successors, (470), 397 states have internal predecessors, (470), 61 states have call successors, (61), 57 states have call predecessors, (61), 56 states have return successors, (89), 55 states have call predecessors, (89), 61 states have call successors, (89) [2022-11-02 20:51:18,799 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 486 states to 486 states and 620 transitions. [2022-11-02 20:51:18,799 INFO L78 Accepts]: Start accepts. Automaton has 486 states and 620 transitions. Word has length 30 [2022-11-02 20:51:18,800 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:18,800 INFO L495 AbstractCegarLoop]: Abstraction has 486 states and 620 transitions. [2022-11-02 20:51:18,801 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:18,801 INFO L276 IsEmpty]: Start isEmpty. Operand 486 states and 620 transitions. [2022-11-02 20:51:18,802 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-02 20:51:18,803 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:18,803 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:18,803 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-02 20:51:18,804 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:18,804 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:18,804 INFO L85 PathProgramCache]: Analyzing trace with hash -129157540, now seen corresponding path program 1 times [2022-11-02 20:51:18,804 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:18,805 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1395208955] [2022-11-02 20:51:18,805 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:18,805 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:18,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:18,931 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:18,932 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:18,936 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:18,936 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:18,936 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1395208955] [2022-11-02 20:51:18,936 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1395208955] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:18,936 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:18,937 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:51:18,937 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1134434871] [2022-11-02 20:51:18,937 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:18,938 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:51:18,938 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:18,939 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:51:18,939 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:51:18,939 INFO L87 Difference]: Start difference. First operand 486 states and 620 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-02 20:51:19,304 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:19,304 INFO L93 Difference]: Finished difference Result 581 states and 747 transitions. [2022-11-02 20:51:19,305 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-11-02 20:51:19,305 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-11-02 20:51:19,305 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:19,309 INFO L225 Difference]: With dead ends: 581 [2022-11-02 20:51:19,309 INFO L226 Difference]: Without dead ends: 579 [2022-11-02 20:51:19,310 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:51:19,314 INFO L413 NwaCegarLoop]: 116 mSDtfsCounter, 160 mSDsluCounter, 235 mSDsCounter, 0 mSdLazyCounter, 241 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 168 SdHoareTripleChecker+Valid, 351 SdHoareTripleChecker+Invalid, 290 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 241 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:19,316 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [168 Valid, 351 Invalid, 290 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 241 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:51:19,318 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 579 states. [2022-11-02 20:51:19,383 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 579 to 550. [2022-11-02 20:51:19,385 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 550 states, 415 states have (on average 1.2626506024096384) internal successors, (524), 455 states have internal predecessors, (524), 69 states have call successors, (69), 57 states have call predecessors, (69), 65 states have return successors, (110), 61 states have call predecessors, (110), 69 states have call successors, (110) [2022-11-02 20:51:19,389 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 550 states to 550 states and 703 transitions. [2022-11-02 20:51:19,390 INFO L78 Accepts]: Start accepts. Automaton has 550 states and 703 transitions. Word has length 32 [2022-11-02 20:51:19,392 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:19,392 INFO L495 AbstractCegarLoop]: Abstraction has 550 states and 703 transitions. [2022-11-02 20:51:19,392 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-02 20:51:19,392 INFO L276 IsEmpty]: Start isEmpty. Operand 550 states and 703 transitions. [2022-11-02 20:51:19,396 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2022-11-02 20:51:19,396 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:19,396 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:19,397 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-02 20:51:19,397 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:19,398 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:19,398 INFO L85 PathProgramCache]: Analyzing trace with hash -1897123065, now seen corresponding path program 1 times [2022-11-02 20:51:19,398 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:19,400 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1658757340] [2022-11-02 20:51:19,400 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:19,401 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:19,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:19,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:19,513 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:19,517 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:51:19,522 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:19,537 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:19,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:19,567 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:19,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:19,571 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:19,572 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:19,572 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1658757340] [2022-11-02 20:51:19,572 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1658757340] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:19,572 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:19,572 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:51:19,573 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [304006223] [2022-11-02 20:51:19,573 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:19,573 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:51:19,573 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:19,574 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:51:19,574 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:51:19,574 INFO L87 Difference]: Start difference. First operand 550 states and 703 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:20,007 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:20,008 INFO L93 Difference]: Finished difference Result 1071 states and 1420 transitions. [2022-11-02 20:51:20,008 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-02 20:51:20,008 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2022-11-02 20:51:20,009 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:20,012 INFO L225 Difference]: With dead ends: 1071 [2022-11-02 20:51:20,013 INFO L226 Difference]: Without dead ends: 728 [2022-11-02 20:51:20,014 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=47, Invalid=85, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:51:20,018 INFO L413 NwaCegarLoop]: 123 mSDtfsCounter, 179 mSDsluCounter, 185 mSDsCounter, 0 mSdLazyCounter, 259 mSolverCounterSat, 68 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 180 SdHoareTripleChecker+Valid, 308 SdHoareTripleChecker+Invalid, 327 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 68 IncrementalHoareTripleChecker+Valid, 259 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:20,018 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [180 Valid, 308 Invalid, 327 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [68 Valid, 259 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-02 20:51:20,020 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 728 states. [2022-11-02 20:51:20,082 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 728 to 602. [2022-11-02 20:51:20,083 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 602 states, 457 states have (on average 1.2516411378555798) internal successors, (572), 497 states have internal predecessors, (572), 69 states have call successors, (69), 57 states have call predecessors, (69), 75 states have return successors, (124), 69 states have call predecessors, (124), 69 states have call successors, (124) [2022-11-02 20:51:20,087 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 602 states to 602 states and 765 transitions. [2022-11-02 20:51:20,088 INFO L78 Accepts]: Start accepts. Automaton has 602 states and 765 transitions. Word has length 55 [2022-11-02 20:51:20,089 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:20,089 INFO L495 AbstractCegarLoop]: Abstraction has 602 states and 765 transitions. [2022-11-02 20:51:20,089 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:20,090 INFO L276 IsEmpty]: Start isEmpty. Operand 602 states and 765 transitions. [2022-11-02 20:51:20,092 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2022-11-02 20:51:20,092 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:20,092 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:20,093 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-02 20:51:20,093 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:20,093 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:20,093 INFO L85 PathProgramCache]: Analyzing trace with hash -2031136571, now seen corresponding path program 1 times [2022-11-02 20:51:20,094 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:20,094 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1295709782] [2022-11-02 20:51:20,095 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:20,099 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:20,121 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:20,246 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:20,247 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:20,254 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:51:20,258 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:20,268 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:20,271 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:20,282 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:20,284 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:20,286 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:20,287 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:20,287 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1295709782] [2022-11-02 20:51:20,287 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1295709782] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:20,287 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:20,287 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-02 20:51:20,287 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1372840922] [2022-11-02 20:51:20,288 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:20,288 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-02 20:51:20,288 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:20,288 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-02 20:51:20,289 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:51:20,289 INFO L87 Difference]: Start difference. First operand 602 states and 765 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:20,899 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:20,899 INFO L93 Difference]: Finished difference Result 1268 states and 1714 transitions. [2022-11-02 20:51:20,900 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-02 20:51:20,900 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2022-11-02 20:51:20,900 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:20,905 INFO L225 Difference]: With dead ends: 1268 [2022-11-02 20:51:20,905 INFO L226 Difference]: Without dead ends: 873 [2022-11-02 20:51:20,908 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 10 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 56 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-11-02 20:51:20,909 INFO L413 NwaCegarLoop]: 160 mSDtfsCounter, 221 mSDsluCounter, 329 mSDsCounter, 0 mSdLazyCounter, 472 mSolverCounterSat, 84 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 224 SdHoareTripleChecker+Valid, 489 SdHoareTripleChecker+Invalid, 556 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 84 IncrementalHoareTripleChecker+Valid, 472 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:20,909 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [224 Valid, 489 Invalid, 556 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [84 Valid, 472 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-02 20:51:20,911 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 873 states. [2022-11-02 20:51:20,990 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 873 to 824. [2022-11-02 20:51:20,991 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 824 states, 628 states have (on average 1.2356687898089171) internal successors, (776), 676 states have internal predecessors, (776), 93 states have call successors, (93), 81 states have call predecessors, (93), 102 states have return successors, (208), 101 states have call predecessors, (208), 93 states have call successors, (208) [2022-11-02 20:51:20,997 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 824 states to 824 states and 1077 transitions. [2022-11-02 20:51:20,997 INFO L78 Accepts]: Start accepts. Automaton has 824 states and 1077 transitions. Word has length 55 [2022-11-02 20:51:20,999 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:20,999 INFO L495 AbstractCegarLoop]: Abstraction has 824 states and 1077 transitions. [2022-11-02 20:51:20,999 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:21,000 INFO L276 IsEmpty]: Start isEmpty. Operand 824 states and 1077 transitions. [2022-11-02 20:51:21,001 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2022-11-02 20:51:21,002 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:21,002 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:21,002 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-02 20:51:21,003 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:21,003 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:21,003 INFO L85 PathProgramCache]: Analyzing trace with hash -1959162679, now seen corresponding path program 1 times [2022-11-02 20:51:21,003 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:21,004 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [810497895] [2022-11-02 20:51:21,004 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:21,004 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:21,027 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,105 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:21,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,111 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:51:21,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,127 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:21,138 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,179 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:21,180 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,191 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:21,191 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:21,191 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [810497895] [2022-11-02 20:51:21,191 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [810497895] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:21,191 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:21,192 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-02 20:51:21,195 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1394250867] [2022-11-02 20:51:21,196 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:21,197 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-02 20:51:21,197 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:21,198 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-02 20:51:21,198 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:51:21,198 INFO L87 Difference]: Start difference. First operand 824 states and 1077 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:21,598 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:21,598 INFO L93 Difference]: Finished difference Result 1719 states and 2316 transitions. [2022-11-02 20:51:21,598 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-02 20:51:21,599 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2022-11-02 20:51:21,599 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:21,605 INFO L225 Difference]: With dead ends: 1719 [2022-11-02 20:51:21,605 INFO L226 Difference]: Without dead ends: 902 [2022-11-02 20:51:21,609 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:51:21,611 INFO L413 NwaCegarLoop]: 103 mSDtfsCounter, 160 mSDsluCounter, 244 mSDsCounter, 0 mSdLazyCounter, 315 mSolverCounterSat, 63 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 347 SdHoareTripleChecker+Invalid, 378 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 63 IncrementalHoareTripleChecker+Valid, 315 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:21,612 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [161 Valid, 347 Invalid, 378 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [63 Valid, 315 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:51:21,613 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 902 states. [2022-11-02 20:51:21,714 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 902 to 836. [2022-11-02 20:51:21,716 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 836 states, 640 states have (on average 1.23125) internal successors, (788), 688 states have internal predecessors, (788), 93 states have call successors, (93), 81 states have call predecessors, (93), 102 states have return successors, (208), 101 states have call predecessors, (208), 93 states have call successors, (208) [2022-11-02 20:51:21,721 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 836 states to 836 states and 1089 transitions. [2022-11-02 20:51:21,722 INFO L78 Accepts]: Start accepts. Automaton has 836 states and 1089 transitions. Word has length 55 [2022-11-02 20:51:21,722 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:21,722 INFO L495 AbstractCegarLoop]: Abstraction has 836 states and 1089 transitions. [2022-11-02 20:51:21,722 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:21,722 INFO L276 IsEmpty]: Start isEmpty. Operand 836 states and 1089 transitions. [2022-11-02 20:51:21,724 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2022-11-02 20:51:21,724 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:21,724 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:21,725 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-02 20:51:21,725 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:21,725 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:21,725 INFO L85 PathProgramCache]: Analyzing trace with hash -2093176185, now seen corresponding path program 1 times [2022-11-02 20:51:21,726 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:21,726 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1448716788] [2022-11-02 20:51:21,726 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:21,726 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:21,740 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,793 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:21,794 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:51:21,802 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,817 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:21,820 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,846 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:21,847 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:21,849 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:21,850 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:21,850 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1448716788] [2022-11-02 20:51:21,850 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1448716788] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:21,850 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:51:21,850 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:51:21,850 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [651634049] [2022-11-02 20:51:21,851 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:21,851 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:51:21,851 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:21,851 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:51:21,852 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:51:21,852 INFO L87 Difference]: Start difference. First operand 836 states and 1089 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:22,155 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:22,155 INFO L93 Difference]: Finished difference Result 1546 states and 2060 transitions. [2022-11-02 20:51:22,156 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:51:22,156 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2022-11-02 20:51:22,157 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:22,161 INFO L225 Difference]: With dead ends: 1546 [2022-11-02 20:51:22,161 INFO L226 Difference]: Without dead ends: 717 [2022-11-02 20:51:22,164 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-02 20:51:22,165 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 164 mSDsluCounter, 189 mSDsCounter, 0 mSdLazyCounter, 234 mSolverCounterSat, 59 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 165 SdHoareTripleChecker+Valid, 290 SdHoareTripleChecker+Invalid, 293 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 59 IncrementalHoareTripleChecker+Valid, 234 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:22,166 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [165 Valid, 290 Invalid, 293 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [59 Valid, 234 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:51:22,167 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 717 states. [2022-11-02 20:51:22,265 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 717 to 697. [2022-11-02 20:51:22,266 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 697 states, 531 states have (on average 1.2241054613935969) internal successors, (650), 570 states have internal predecessors, (650), 82 states have call successors, (82), 70 states have call predecessors, (82), 83 states have return successors, (163), 84 states have call predecessors, (163), 82 states have call successors, (163) [2022-11-02 20:51:22,272 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 697 states to 697 states and 895 transitions. [2022-11-02 20:51:22,272 INFO L78 Accepts]: Start accepts. Automaton has 697 states and 895 transitions. Word has length 55 [2022-11-02 20:51:22,272 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:22,273 INFO L495 AbstractCegarLoop]: Abstraction has 697 states and 895 transitions. [2022-11-02 20:51:22,273 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-02 20:51:22,273 INFO L276 IsEmpty]: Start isEmpty. Operand 697 states and 895 transitions. [2022-11-02 20:51:22,278 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2022-11-02 20:51:22,278 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:22,279 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:22,279 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-11-02 20:51:22,279 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:22,280 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:22,280 INFO L85 PathProgramCache]: Analyzing trace with hash 1124052112, now seen corresponding path program 1 times [2022-11-02 20:51:22,280 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:22,280 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1860897549] [2022-11-02 20:51:22,280 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:22,281 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:22,317 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,488 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:22,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,499 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:51:22,504 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,522 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:51:22,525 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,534 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:22,537 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,547 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:22,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,551 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2022-11-02 20:51:22,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,555 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-11-02 20:51:22,562 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,566 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:51:22,567 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,569 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:22,570 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,572 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 11 proven. 9 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-02 20:51:22,573 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:22,573 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1860897549] [2022-11-02 20:51:22,573 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1860897549] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:51:22,573 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1668174598] [2022-11-02 20:51:22,573 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:22,573 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:22,574 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:51:22,576 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:51:22,604 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-02 20:51:22,709 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:22,713 INFO L263 TraceCheckSpWp]: Trace formula consists of 483 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-02 20:51:22,720 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:51:22,901 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 16 proven. 12 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:51:22,901 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-02 20:51:23,135 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 12 proven. 8 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-02 20:51:23,136 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1668174598] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-02 20:51:23,136 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-02 20:51:23,136 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-11-02 20:51:23,136 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2020772741] [2022-11-02 20:51:23,136 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-02 20:51:23,137 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-02 20:51:23,137 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:23,137 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-02 20:51:23,138 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-11-02 20:51:23,138 INFO L87 Difference]: Start difference. First operand 697 states and 895 transitions. Second operand has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-02 20:51:24,088 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:24,089 INFO L93 Difference]: Finished difference Result 1672 states and 2265 transitions. [2022-11-02 20:51:24,090 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-11-02 20:51:24,090 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 101 [2022-11-02 20:51:24,090 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:24,108 INFO L225 Difference]: With dead ends: 1672 [2022-11-02 20:51:24,109 INFO L226 Difference]: Without dead ends: 1099 [2022-11-02 20:51:24,111 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 254 GetRequests, 218 SyntacticMatches, 9 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 204 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-11-02 20:51:24,112 INFO L413 NwaCegarLoop]: 148 mSDtfsCounter, 395 mSDsluCounter, 401 mSDsCounter, 0 mSdLazyCounter, 629 mSolverCounterSat, 168 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 403 SdHoareTripleChecker+Valid, 549 SdHoareTripleChecker+Invalid, 797 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 168 IncrementalHoareTripleChecker+Valid, 629 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:24,113 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [403 Valid, 549 Invalid, 797 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [168 Valid, 629 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-02 20:51:24,114 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1099 states. [2022-11-02 20:51:24,207 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1099 to 964. [2022-11-02 20:51:24,209 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 964 states, 726 states have (on average 1.2314049586776858) internal successors, (894), 783 states have internal predecessors, (894), 119 states have call successors, (119), 101 states have call predecessors, (119), 118 states have return successors, (250), 113 states have call predecessors, (250), 119 states have call successors, (250) [2022-11-02 20:51:24,215 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 964 states to 964 states and 1263 transitions. [2022-11-02 20:51:24,215 INFO L78 Accepts]: Start accepts. Automaton has 964 states and 1263 transitions. Word has length 101 [2022-11-02 20:51:24,216 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:24,216 INFO L495 AbstractCegarLoop]: Abstraction has 964 states and 1263 transitions. [2022-11-02 20:51:24,216 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-02 20:51:24,216 INFO L276 IsEmpty]: Start isEmpty. Operand 964 states and 1263 transitions. [2022-11-02 20:51:24,220 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2022-11-02 20:51:24,220 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:24,221 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:24,261 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-02 20:51:24,448 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:24,448 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:24,448 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:24,449 INFO L85 PathProgramCache]: Analyzing trace with hash -159048421, now seen corresponding path program 2 times [2022-11-02 20:51:24,449 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:24,449 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [708077300] [2022-11-02 20:51:24,449 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:24,449 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:24,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,728 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:24,729 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,741 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:51:24,744 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,760 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:51:24,763 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,773 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:24,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,791 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:24,792 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-11-02 20:51:24,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2022-11-02 20:51:24,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:24,899 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:51:24,904 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,026 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:51:25,027 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,038 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:25,039 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,041 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2022-11-02 20:51:25,042 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,044 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2022-11-02 20:51:25,050 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,058 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:51:25,059 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,060 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:25,061 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:25,063 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 49 proven. 23 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-11-02 20:51:25,063 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:25,063 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [708077300] [2022-11-02 20:51:25,063 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [708077300] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:51:25,063 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [223514614] [2022-11-02 20:51:25,063 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-11-02 20:51:25,064 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:25,064 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:51:25,065 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:51:25,088 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-02 20:51:25,220 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-11-02 20:51:25,220 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-11-02 20:51:25,223 INFO L263 TraceCheckSpWp]: Trace formula consists of 597 conjuncts, 10 conjunts are in the unsatisfiable core [2022-11-02 20:51:25,227 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:51:25,328 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 84 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-11-02 20:51:25,328 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-02 20:51:25,329 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [223514614] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:25,329 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-02 20:51:25,329 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 12 [2022-11-02 20:51:25,329 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [866197644] [2022-11-02 20:51:25,329 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:25,330 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:51:25,330 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:25,330 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:51:25,331 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:51:25,331 INFO L87 Difference]: Start difference. First operand 964 states and 1263 transitions. Second operand has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-02 20:51:25,819 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:25,819 INFO L93 Difference]: Finished difference Result 2581 states and 3531 transitions. [2022-11-02 20:51:25,819 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-02 20:51:25,819 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 147 [2022-11-02 20:51:25,820 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:25,828 INFO L225 Difference]: With dead ends: 2581 [2022-11-02 20:51:25,829 INFO L226 Difference]: Without dead ends: 1739 [2022-11-02 20:51:25,833 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 193 GetRequests, 175 SyntacticMatches, 3 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=57, Invalid=215, Unknown=0, NotChecked=0, Total=272 [2022-11-02 20:51:25,834 INFO L413 NwaCegarLoop]: 204 mSDtfsCounter, 244 mSDsluCounter, 472 mSDsCounter, 0 mSdLazyCounter, 165 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 244 SdHoareTripleChecker+Valid, 676 SdHoareTripleChecker+Invalid, 214 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 165 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:25,834 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [244 Valid, 676 Invalid, 214 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 165 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:51:25,836 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1739 states. [2022-11-02 20:51:25,973 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1739 to 1703. [2022-11-02 20:51:25,977 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1703 states, 1286 states have (on average 1.2301710730948678) internal successors, (1582), 1370 states have internal predecessors, (1582), 202 states have call successors, (202), 180 states have call predecessors, (202), 214 states have return successors, (404), 204 states have call predecessors, (404), 202 states have call successors, (404) [2022-11-02 20:51:25,986 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1703 states to 1703 states and 2188 transitions. [2022-11-02 20:51:25,987 INFO L78 Accepts]: Start accepts. Automaton has 1703 states and 2188 transitions. Word has length 147 [2022-11-02 20:51:25,987 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:25,987 INFO L495 AbstractCegarLoop]: Abstraction has 1703 states and 2188 transitions. [2022-11-02 20:51:25,988 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-02 20:51:25,988 INFO L276 IsEmpty]: Start isEmpty. Operand 1703 states and 2188 transitions. [2022-11-02 20:51:26,012 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2022-11-02 20:51:26,012 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:51:26,012 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:26,053 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-02 20:51:26,236 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:26,236 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:51:26,236 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:51:26,237 INFO L85 PathProgramCache]: Analyzing trace with hash -1375202147, now seen corresponding path program 1 times [2022-11-02 20:51:26,237 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:51:26,237 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1258672954] [2022-11-02 20:51:26,237 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:26,237 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:51:26,261 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,376 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-02 20:51:26,377 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,385 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:51:26,388 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,397 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-02 20:51:26,399 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,402 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:26,404 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,407 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:51:26,408 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,410 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-11-02 20:51:26,414 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,429 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2022-11-02 20:51:26,430 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,432 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:51:26,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,465 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:51:26,466 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,468 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:26,468 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,469 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2022-11-02 20:51:26,470 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,472 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2022-11-02 20:51:26,475 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,477 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-02 20:51:26,479 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:51:26,481 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,482 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 53 trivial. 0 not checked. [2022-11-02 20:51:26,482 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:51:26,482 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1258672954] [2022-11-02 20:51:26,482 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1258672954] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:51:26,482 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [662906227] [2022-11-02 20:51:26,482 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:51:26,482 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:26,483 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:51:26,483 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:51:26,504 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-02 20:51:26,623 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:51:26,626 INFO L263 TraceCheckSpWp]: Trace formula consists of 598 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-02 20:51:26,634 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:51:26,655 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 70 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2022-11-02 20:51:26,655 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-02 20:51:26,656 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [662906227] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:51:26,656 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-02 20:51:26,656 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [10] total 10 [2022-11-02 20:51:26,656 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1208912280] [2022-11-02 20:51:26,656 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:51:26,657 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:51:26,657 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:51:26,657 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:51:26,657 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=19, Invalid=71, Unknown=0, NotChecked=0, Total=90 [2022-11-02 20:51:26,658 INFO L87 Difference]: Start difference. First operand 1703 states and 2188 transitions. Second operand has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2022-11-02 20:51:26,764 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:51:26,765 INFO L93 Difference]: Finished difference Result 2351 states and 2994 transitions. [2022-11-02 20:51:26,765 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:51:26,765 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) Word has length 147 [2022-11-02 20:51:26,766 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:51:26,766 INFO L225 Difference]: With dead ends: 2351 [2022-11-02 20:51:26,767 INFO L226 Difference]: Without dead ends: 0 [2022-11-02 20:51:26,772 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 187 GetRequests, 177 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=29, Invalid=103, Unknown=0, NotChecked=0, Total=132 [2022-11-02 20:51:26,773 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 9 mSDsluCounter, 325 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 439 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:51:26,773 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 439 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:51:26,774 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-02 20:51:26,774 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-02 20:51:26,774 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:51:26,774 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-02 20:51:26,775 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 147 [2022-11-02 20:51:26,775 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:51:26,775 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-02 20:51:26,775 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2022-11-02 20:51:26,775 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-02 20:51:26,775 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-02 20:51:26,778 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-02 20:51:26,814 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-02 20:51:26,992 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:51:26,994 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-02 20:51:31,071 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 841 848) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,072 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 841 848) no Hoare annotation was computed. [2022-11-02 20:51:31,072 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 841 848) no Hoare annotation was computed. [2022-11-02 20:51:31,072 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2022-11-02 20:51:31,072 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2022-11-02 20:51:31,072 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 615 626) the Hoare annotation is: true [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point L619-1(lines 615 626) no Hoare annotation was computed. [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 615 626) no Hoare annotation was computed. [2022-11-02 20:51:31,073 INFO L895 garLoopResultBuilder]: At program point L865(lines 860 868) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point L799(lines 799 807) no Hoare annotation was computed. [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point L795(lines 795 812) no Hoare annotation was computed. [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point L696(line 696) no Hoare annotation was computed. [2022-11-02 20:51:31,073 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 707 730) no Hoare annotation was computed. [2022-11-02 20:51:31,074 INFO L895 garLoopResultBuilder]: At program point L697(lines 692 699) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,074 INFO L895 garLoopResultBuilder]: At program point L664(lines 659 667) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse7 .cse6 .cse8 (not .cse2))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3) (or .cse0 (and .cse5 .cse6) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (and .cse7 .cse8) (and .cse5 (<= 1 ~waterLevel~0) .cse4) .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-02 20:51:31,074 INFO L899 garLoopResultBuilder]: For program point L718-1(lines 718 724) no Hoare annotation was computed. [2022-11-02 20:51:31,074 INFO L895 garLoopResultBuilder]: At program point L805(line 805) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,075 INFO L895 garLoopResultBuilder]: At program point L801(line 801) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,075 INFO L895 garLoopResultBuilder]: At program point L797(line 797) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,075 INFO L899 garLoopResultBuilder]: For program point L797-1(line 797) no Hoare annotation was computed. [2022-11-02 20:51:31,075 INFO L899 garLoopResultBuilder]: For program point L570(lines 570 576) no Hoare annotation was computed. [2022-11-02 20:51:31,075 INFO L899 garLoopResultBuilder]: For program point L566(lines 566 579) no Hoare annotation was computed. [2022-11-02 20:51:31,076 INFO L895 garLoopResultBuilder]: At program point L566-1(lines 558 582) the Hoare annotation is: (let ((.cse8 (<= 2 ~waterLevel~0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse9 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse10 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse7 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (and .cse8 .cse2 .cse9 .cse10 (not .cse7))) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse6 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 (and .cse4 .cse5) .cse6) (or .cse0 .cse3 .cse7 .cse6) (or (and .cse1 (<= 1 ~waterLevel~0) .cse4 .cse5) (and .cse8 .cse9 .cse10) .cse7 .cse6)))) [2022-11-02 20:51:31,076 INFO L899 garLoopResultBuilder]: For program point L595(lines 595 599) no Hoare annotation was computed. [2022-11-02 20:51:31,076 INFO L895 garLoopResultBuilder]: At program point L595-2(lines 591 602) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-02 20:51:31,077 INFO L895 garLoopResultBuilder]: At program point L810(line 810) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-11-02 20:51:31,077 INFO L895 garLoopResultBuilder]: At program point L810-1(lines 791 815) the Hoare annotation is: (let ((.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0)) (.cse0 (= ~pumpRunning~0 0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or .cse3 .cse4 (and .cse0 (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-02 20:51:31,077 INFO L899 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2022-11-02 20:51:31,077 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 707 730) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-02 20:51:31,077 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2022-11-02 20:51:31,078 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 696) no Hoare annotation was computed. [2022-11-02 20:51:31,078 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 418 447) no Hoare annotation was computed. [2022-11-02 20:51:31,078 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 418 447) the Hoare annotation is: true [2022-11-02 20:51:31,078 INFO L902 garLoopResultBuilder]: At program point L443(lines 418 447) the Hoare annotation is: true [2022-11-02 20:51:31,078 INFO L899 garLoopResultBuilder]: For program point L439(line 439) no Hoare annotation was computed. [2022-11-02 20:51:31,078 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2022-11-02 20:51:31,078 INFO L902 garLoopResultBuilder]: At program point L432-1(lines 432 436) the Hoare annotation is: true [2022-11-02 20:51:31,079 INFO L899 garLoopResultBuilder]: For program point L429(line 429) no Hoare annotation was computed. [2022-11-02 20:51:31,079 INFO L902 garLoopResultBuilder]: At program point L428-2(lines 428 442) the Hoare annotation is: true [2022-11-02 20:51:31,079 INFO L902 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: true [2022-11-02 20:51:31,079 INFO L899 garLoopResultBuilder]: For program point L424-1(line 424) no Hoare annotation was computed. [2022-11-02 20:51:31,079 INFO L899 garLoopResultBuilder]: For program point L989(lines 989 995) no Hoare annotation was computed. [2022-11-02 20:51:31,079 INFO L899 garLoopResultBuilder]: For program point L989-1(lines 989 995) no Hoare annotation was computed. [2022-11-02 20:51:31,079 INFO L899 garLoopResultBuilder]: For program point L506(lines 506 513) no Hoare annotation was computed. [2022-11-02 20:51:31,080 INFO L899 garLoopResultBuilder]: For program point L506-2(lines 506 513) no Hoare annotation was computed. [2022-11-02 20:51:31,080 INFO L895 garLoopResultBuilder]: At program point L535(lines 531 537) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:51:31,080 INFO L895 garLoopResultBuilder]: At program point L1014(lines 969 1016) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2022-11-02 20:51:31,080 INFO L895 garLoopResultBuilder]: At program point L981(line 981) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2022-11-02 20:51:31,080 INFO L902 garLoopResultBuilder]: At program point L490(lines 483 492) the Hoare annotation is: true [2022-11-02 20:51:31,081 INFO L902 garLoopResultBuilder]: At program point L515(lines 496 518) the Hoare annotation is: true [2022-11-02 20:51:31,081 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-02 20:51:31,081 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-02 20:51:31,081 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-02 20:51:31,081 INFO L895 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (and (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-11-02 20:51:31,081 INFO L899 garLoopResultBuilder]: For program point L970(lines 969 1016) no Hoare annotation was computed. [2022-11-02 20:51:31,082 INFO L899 garLoopResultBuilder]: For program point L999(lines 999 1012) no Hoare annotation was computed. [2022-11-02 20:51:31,082 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-02 20:51:31,082 INFO L895 garLoopResultBuilder]: At program point L479(lines 475 481) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:51:31,082 INFO L895 garLoopResultBuilder]: At program point L991(line 991) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2022-11-02 20:51:31,082 INFO L902 garLoopResultBuilder]: At program point L1020(lines 959 1024) the Hoare annotation is: true [2022-11-02 20:51:31,082 INFO L899 garLoopResultBuilder]: For program point L979(lines 979 985) no Hoare annotation was computed. [2022-11-02 20:51:31,083 INFO L899 garLoopResultBuilder]: For program point L979-1(lines 979 985) no Hoare annotation was computed. [2022-11-02 20:51:31,083 INFO L899 garLoopResultBuilder]: For program point L971(lines 971 975) no Hoare annotation was computed. [2022-11-02 20:51:31,083 INFO L895 garLoopResultBuilder]: At program point L550(lines 545 553) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:51:31,083 INFO L895 garLoopResultBuilder]: At program point L542(lines 538 544) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-02 20:51:31,083 INFO L895 garLoopResultBuilder]: At program point L955(lines 943 957) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-11-02 20:51:31,083 INFO L895 garLoopResultBuilder]: At program point L1017(lines 968 1018) the Hoare annotation is: false [2022-11-02 20:51:31,084 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2022-11-02 20:51:31,084 INFO L899 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2022-11-02 20:51:31,084 INFO L899 garLoopResultBuilder]: For program point L1005(lines 1005 1011) no Hoare annotation was computed. [2022-11-02 20:51:31,084 INFO L895 garLoopResultBuilder]: At program point L1005-2(lines 999 1012) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2022-11-02 20:51:31,084 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 739 763) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,085 INFO L895 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,085 INFO L899 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2022-11-02 20:51:31,085 INFO L899 garLoopResultBuilder]: For program point L672(lines 672 678) no Hoare annotation was computed. [2022-11-02 20:51:31,085 INFO L899 garLoopResultBuilder]: For program point L831(lines 831 837) no Hoare annotation was computed. [2022-11-02 20:51:31,085 INFO L895 garLoopResultBuilder]: At program point L829(line 829) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,085 INFO L895 garLoopResultBuilder]: At program point L831-2(lines 824 840) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,085 INFO L899 garLoopResultBuilder]: For program point L829-1(line 829) no Hoare annotation was computed. [2022-11-02 20:51:31,086 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2022-11-02 20:51:31,086 INFO L895 garLoopResultBuilder]: At program point L920(lines 905 923) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)) .cse2) (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) .cse2))) [2022-11-02 20:51:31,086 INFO L895 garLoopResultBuilder]: At program point L821(lines 816 823) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,086 INFO L899 garLoopResultBuilder]: For program point L914(lines 914 918) no Hoare annotation was computed. [2022-11-02 20:51:31,086 INFO L895 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 .cse1 .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)) (not (<= 1 ~waterLevel~0)) (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-11-02 20:51:31,087 INFO L899 garLoopResultBuilder]: For program point L914-2(lines 914 918) no Hoare annotation was computed. [2022-11-02 20:51:31,087 INFO L899 garLoopResultBuilder]: For program point L747(lines 747 755) no Hoare annotation was computed. [2022-11-02 20:51:31,087 INFO L899 garLoopResultBuilder]: For program point L743(lines 743 760) no Hoare annotation was computed. [2022-11-02 20:51:31,087 INFO L895 garLoopResultBuilder]: At program point L677(lines 668 681) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse4 (<= 2 ~waterLevel~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))) (and (or .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)) (not (<= 1 ~waterLevel~0)) .cse2 .cse3) (or .cse0 (not .cse4) .cse2 .cse3)))) [2022-11-02 20:51:31,087 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 603 614) no Hoare annotation was computed. [2022-11-02 20:51:31,087 INFO L899 garLoopResultBuilder]: For program point L607-1(lines 603 614) no Hoare annotation was computed. [2022-11-02 20:51:31,087 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 603 614) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-02 20:51:31,088 INFO L895 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,088 INFO L895 garLoopResultBuilder]: At program point L775(line 775) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_~tmp~6#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (= |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp~10#1| 0))))) [2022-11-02 20:51:31,088 INFO L899 garLoopResultBuilder]: For program point L773(lines 773 781) no Hoare annotation was computed. [2022-11-02 20:51:31,088 INFO L899 garLoopResultBuilder]: For program point L769(lines 769 786) no Hoare annotation was computed. [2022-11-02 20:51:31,088 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 765 789) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,089 INFO L895 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0)) (= 0 ~systemActive~0)) [2022-11-02 20:51:31,089 INFO L895 garLoopResultBuilder]: At program point L687(lines 682 690) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-02 20:51:31,089 INFO L899 garLoopResultBuilder]: For program point L784-1(lines 765 789) no Hoare annotation was computed. [2022-11-02 20:51:31,089 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 765 789) no Hoare annotation was computed. [2022-11-02 20:51:31,089 INFO L895 garLoopResultBuilder]: At program point L939(lines 924 942) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (= |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp~10#1| 0)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-02 20:51:31,089 INFO L899 garLoopResultBuilder]: For program point L933(lines 933 937) no Hoare annotation was computed. [2022-11-02 20:51:31,090 INFO L899 garLoopResultBuilder]: For program point L933-2(lines 933 937) no Hoare annotation was computed. [2022-11-02 20:51:31,090 INFO L902 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 849 859) the Hoare annotation is: true [2022-11-02 20:51:31,090 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 849 859) no Hoare annotation was computed. [2022-11-02 20:51:31,090 INFO L902 garLoopResultBuilder]: At program point L632(lines 627 635) the Hoare annotation is: true [2022-11-02 20:51:31,090 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 849 859) no Hoare annotation was computed. [2022-11-02 20:51:31,093 INFO L444 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:51:31,095 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-02 20:51:31,118 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 02.11 08:51:31 BoogieIcfgContainer [2022-11-02 20:51:31,118 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-02 20:51:31,118 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-02 20:51:31,119 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-02 20:51:31,119 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-02 20:51:31,119 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:51:16" (3/4) ... [2022-11-02 20:51:31,122 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-02 20:51:31,128 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-02 20:51:31,128 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-02 20:51:31,128 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2022-11-02 20:51:31,129 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2022-11-02 20:51:31,137 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-02 20:51:31,137 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-02 20:51:31,138 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-02 20:51:31,138 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-02 20:51:31,139 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-02 20:51:31,139 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:51:31,140 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:51:31,160 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-11-02 20:51:31,160 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-11-02 20:51:31,161 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-02 20:51:31,162 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-02 20:51:31,162 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-11-02 20:51:31,163 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((((((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-02 20:51:31,163 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-11-02 20:51:31,164 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-11-02 20:51:31,164 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-11-02 20:51:31,164 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= waterLevel)) || 0 == systemActive) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && \result == 0)) && (((!(\old(pumpRunning) == 0) || !(2 <= waterLevel)) || 0 == systemActive) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && \result == 0)) [2022-11-02 20:51:31,164 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-11-02 20:51:31,164 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == \old(pumpRunning) && 1 <= tmp___0) && 1 <= \result) && \result == 0) && tmp == 0) || !(1 <= waterLevel)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-11-02 20:51:31,165 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-11-02 20:51:31,165 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == 0 && tmp___0 == 0) && tmp == 1) && \result == 0) && \result == 1)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) [2022-11-02 20:51:31,194 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/witness.graphml [2022-11-02 20:51:31,194 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-02 20:51:31,195 INFO L158 Benchmark]: Toolchain (without parser) took 15991.03ms. Allocated memory was 119.5MB in the beginning and 251.7MB in the end (delta: 132.1MB). Free memory was 79.6MB in the beginning and 184.3MB in the end (delta: -104.7MB). Peak memory consumption was 26.3MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,195 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 119.5MB. Free memory is still 97.4MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-02 20:51:31,195 INFO L158 Benchmark]: CACSL2BoogieTranslator took 698.18ms. Allocated memory is still 119.5MB. Free memory was 79.4MB in the beginning and 86.1MB in the end (delta: -6.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,196 INFO L158 Benchmark]: Boogie Procedure Inliner took 67.80ms. Allocated memory is still 119.5MB. Free memory was 86.1MB in the beginning and 83.6MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,196 INFO L158 Benchmark]: Boogie Preprocessor took 32.63ms. Allocated memory is still 119.5MB. Free memory was 83.6MB in the beginning and 81.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,196 INFO L158 Benchmark]: RCFGBuilder took 672.87ms. Allocated memory is still 119.5MB. Free memory was 81.9MB in the beginning and 61.9MB in the end (delta: 20.0MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,197 INFO L158 Benchmark]: TraceAbstraction took 14436.20ms. Allocated memory was 119.5MB in the beginning and 251.7MB in the end (delta: 132.1MB). Free memory was 61.0MB in the beginning and 190.6MB in the end (delta: -129.7MB). Peak memory consumption was 116.7MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,197 INFO L158 Benchmark]: Witness Printer took 75.87ms. Allocated memory is still 251.7MB. Free memory was 190.6MB in the beginning and 184.3MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-02 20:51:31,199 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 119.5MB. Free memory is still 97.4MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 698.18ms. Allocated memory is still 119.5MB. Free memory was 79.4MB in the beginning and 86.1MB in the end (delta: -6.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 67.80ms. Allocated memory is still 119.5MB. Free memory was 86.1MB in the beginning and 83.6MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 32.63ms. Allocated memory is still 119.5MB. Free memory was 83.6MB in the beginning and 81.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 672.87ms. Allocated memory is still 119.5MB. Free memory was 81.9MB in the beginning and 61.9MB in the end (delta: 20.0MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 14436.20ms. Allocated memory was 119.5MB in the beginning and 251.7MB in the end (delta: 132.1MB). Free memory was 61.0MB in the beginning and 190.6MB in the end (delta: -129.7MB). Peak memory consumption was 116.7MB. Max. memory is 16.1GB. * Witness Printer took 75.87ms. Allocated memory is still 251.7MB. Free memory was 190.6MB in the beginning and 184.3MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 696]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 107 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 14.3s, OverallIterations: 13, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 4.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.1s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2038 SdHoareTripleChecker+Valid, 2.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2012 mSDsluCounter, 4936 SdHoareTripleChecker+Invalid, 2.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3238 mSDsCounter, 598 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2499 IncrementalHoareTripleChecker+Invalid, 3097 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 598 mSolverCounterUnsat, 1698 mSDtfsCounter, 2499 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 759 GetRequests, 626 SyntacticMatches, 14 SemanticMatches, 119 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 324 ImplicationChecksByTransitivity, 0.9s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1703occurred in iteration=12, InterpolantAutomatonStates: 115, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 1.0s AutomataMinimizationTime, 13 MinimizatonAttempts, 478 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 50 LocationsWithAnnotation, 3415 PreInvPairs, 3678 NumberOfFragments, 1112 HoareAnnotationTreeSize, 3415 FomulaSimplifications, 3454 FormulaSimplificationTreeSizeReduction, 0.8s HoareSimplificationTime, 50 FomulaSimplificationsInter, 16196 FormulaSimplificationTreeSizeReductionInter, 3.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 3.0s InterpolantComputationTime, 1163 NumberOfCodeBlocks, 1163 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 1247 ConstructedInterpolants, 0 QuantifiedInterpolants, 2145 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1678 ConjunctsInSsa, 23 ConjunctsInUnsatCore, 17 InterpolantComputations, 12 PerfectInterpolantSequences, 434/492 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 558]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((((((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 943]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 905]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == 0 && tmp___0 == 0) && tmp == 1) && \result == 0) && \result == 1)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 538]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 496]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 924]: Loop Invariant Derived loop invariant: ((((((pumpRunning == \old(pumpRunning) && 1 <= tmp___0) && 1 <= \result) && \result == 0) && tmp == 0) || !(1 <= waterLevel)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 418]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 860]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 428]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 791]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 682]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 591]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 627]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 483]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 959]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 659]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 692]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 668]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= waterLevel)) || 0 == systemActive) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && \result == 0)) && (((!(\old(pumpRunning) == 0) || !(2 <= waterLevel)) || 0 == systemActive) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && \result == 0)) - InvariantResult [Line: 969]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((2 <= waterLevel && splverifierCounter == 0) && !(0 == systemActive))) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 968]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 545]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 475]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 RESULT: Ultimate proved your program to be correct! [2022-11-02 20:51:31,265 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_577f5a22-66c4-4c1c-8e83-11409b94ee60/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE