./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 68c6d60a43782147acd714b0904a144255717c2aa47fb6b6f8991672a1483369 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-02 20:36:45,762 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-02 20:36:45,765 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-02 20:36:45,827 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-02 20:36:45,828 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-02 20:36:45,834 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-02 20:36:45,836 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-02 20:36:45,841 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-02 20:36:45,843 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-02 20:36:45,850 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-02 20:36:45,851 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-02 20:36:45,853 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-02 20:36:45,854 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-02 20:36:45,857 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-02 20:36:45,859 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-02 20:36:45,862 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-02 20:36:45,864 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-02 20:36:45,865 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-02 20:36:45,867 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-02 20:36:45,876 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-02 20:36:45,879 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-02 20:36:45,880 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-02 20:36:45,884 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-02 20:36:45,885 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-02 20:36:45,892 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-02 20:36:45,897 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-02 20:36:45,897 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-02 20:36:45,898 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-02 20:36:45,900 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-02 20:36:45,901 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-02 20:36:45,902 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-02 20:36:45,905 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-02 20:36:45,907 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-02 20:36:45,909 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-02 20:36:45,910 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-02 20:36:45,911 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-02 20:36:45,912 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-02 20:36:45,912 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-02 20:36:45,912 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-02 20:36:45,913 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-02 20:36:45,914 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-02 20:36:45,915 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-02 20:36:45,966 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-02 20:36:45,966 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-02 20:36:45,967 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-02 20:36:45,967 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-02 20:36:45,968 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-02 20:36:45,969 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-02 20:36:45,970 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-02 20:36:45,970 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-02 20:36:45,970 INFO L138 SettingsManager]: * Use SBE=true [2022-11-02 20:36:45,970 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-02 20:36:45,972 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-02 20:36:45,972 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-02 20:36:45,972 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-02 20:36:45,973 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-02 20:36:45,973 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-02 20:36:45,973 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-02 20:36:45,973 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-02 20:36:45,974 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-02 20:36:45,974 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-02 20:36:45,974 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-02 20:36:45,974 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-02 20:36:45,975 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-02 20:36:45,975 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-02 20:36:45,975 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-02 20:36:45,976 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:36:45,976 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-02 20:36:45,976 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-02 20:36:45,976 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-02 20:36:45,977 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-02 20:36:45,977 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-02 20:36:45,977 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-02 20:36:45,977 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-02 20:36:45,978 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-02 20:36:45,978 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 68c6d60a43782147acd714b0904a144255717c2aa47fb6b6f8991672a1483369 [2022-11-02 20:36:46,317 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-02 20:36:46,344 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-02 20:36:46,347 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-02 20:36:46,349 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-02 20:36:46,350 INFO L275 PluginConnector]: CDTParser initialized [2022-11-02 20:36:46,352 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c [2022-11-02 20:36:46,435 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/data/7293b69b2/13c92669ade44ce0b9199825fff11699/FLAGd0eca5cbf [2022-11-02 20:36:47,183 INFO L306 CDTParser]: Found 1 translation units. [2022-11-02 20:36:47,184 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c [2022-11-02 20:36:47,209 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/data/7293b69b2/13c92669ade44ce0b9199825fff11699/FLAGd0eca5cbf [2022-11-02 20:36:47,440 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/data/7293b69b2/13c92669ade44ce0b9199825fff11699 [2022-11-02 20:36:47,443 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-02 20:36:47,445 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-02 20:36:47,448 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-02 20:36:47,448 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-02 20:36:47,455 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-02 20:36:47,457 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:36:47" (1/1) ... [2022-11-02 20:36:47,458 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7fbb8d79 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:47, skipping insertion in model container [2022-11-02 20:36:47,459 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 02.11 08:36:47" (1/1) ... [2022-11-02 20:36:47,468 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-02 20:36:47,536 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-02 20:36:47,778 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c[1605,1618] [2022-11-02 20:36:47,941 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:36:47,954 INFO L203 MainTranslator]: Completed pre-run [2022-11-02 20:36:47,975 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c[1605,1618] [2022-11-02 20:36:48,104 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-02 20:36:48,124 INFO L208 MainTranslator]: Completed translation [2022-11-02 20:36:48,125 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48 WrapperNode [2022-11-02 20:36:48,125 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-02 20:36:48,126 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-02 20:36:48,127 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-02 20:36:48,127 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-02 20:36:48,136 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,152 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,211 INFO L138 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 259 [2022-11-02 20:36:48,212 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-02 20:36:48,213 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-02 20:36:48,213 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-02 20:36:48,213 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-02 20:36:48,225 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,226 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,229 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,229 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,235 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,241 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,244 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,245 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,249 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-02 20:36:48,250 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-02 20:36:48,250 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-02 20:36:48,250 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-02 20:36:48,252 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (1/1) ... [2022-11-02 20:36:48,260 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-02 20:36:48,287 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:36:48,306 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-02 20:36:48,312 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-02 20:36:48,360 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-02 20:36:48,360 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-02 20:36:48,360 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-02 20:36:48,361 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-02 20:36:48,361 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-02 20:36:48,361 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-02 20:36:48,361 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-02 20:36:48,364 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:36:48,364 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:36:48,364 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-02 20:36:48,364 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-02 20:36:48,364 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-02 20:36:48,365 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-02 20:36:48,365 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-02 20:36:48,365 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-02 20:36:48,365 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-02 20:36:48,365 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-02 20:36:48,365 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-02 20:36:48,458 INFO L235 CfgBuilder]: Building ICFG [2022-11-02 20:36:48,462 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-02 20:36:48,952 INFO L276 CfgBuilder]: Performing block encoding [2022-11-02 20:36:48,960 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-02 20:36:48,960 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-02 20:36:48,962 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:36:48 BoogieIcfgContainer [2022-11-02 20:36:48,963 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-02 20:36:48,965 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-02 20:36:48,965 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-02 20:36:48,970 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-02 20:36:48,970 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 02.11 08:36:47" (1/3) ... [2022-11-02 20:36:48,971 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3c7fcc47 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:36:48, skipping insertion in model container [2022-11-02 20:36:48,971 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 02.11 08:36:48" (2/3) ... [2022-11-02 20:36:48,971 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3c7fcc47 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 02.11 08:36:48, skipping insertion in model container [2022-11-02 20:36:48,972 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:36:48" (3/3) ... [2022-11-02 20:36:48,984 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product38.cil.c [2022-11-02 20:36:49,006 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-02 20:36:49,006 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-02 20:36:49,103 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-02 20:36:49,115 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@1b168d75, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-02 20:36:49,115 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-02 20:36:49,129 INFO L276 IsEmpty]: Start isEmpty. Operand has 91 states, 70 states have (on average 1.3714285714285714) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-02 20:36:49,142 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-02 20:36:49,142 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:49,143 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:49,144 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:49,152 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:49,153 INFO L85 PathProgramCache]: Analyzing trace with hash 849031785, now seen corresponding path program 1 times [2022-11-02 20:36:49,193 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:49,194 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [760985097] [2022-11-02 20:36:49,194 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:49,195 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:49,384 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:49,545 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-11-02 20:36:49,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:49,567 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-02 20:36:49,578 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:49,589 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:49,596 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:49,597 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [760985097] [2022-11-02 20:36:49,598 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [760985097] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:49,598 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:49,598 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-02 20:36:49,600 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2123600242] [2022-11-02 20:36:49,601 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:49,607 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-02 20:36:49,609 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:49,659 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-02 20:36:49,661 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:36:49,665 INFO L87 Difference]: Start difference. First operand has 91 states, 70 states have (on average 1.3714285714285714) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:36:49,747 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:49,748 INFO L93 Difference]: Finished difference Result 173 states and 234 transitions. [2022-11-02 20:36:49,750 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-02 20:36:49,752 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-11-02 20:36:49,752 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:49,770 INFO L225 Difference]: With dead ends: 173 [2022-11-02 20:36:49,770 INFO L226 Difference]: Without dead ends: 82 [2022-11-02 20:36:49,777 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-02 20:36:49,782 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 114 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:49,785 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 114 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:36:49,807 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 82 states. [2022-11-02 20:36:49,859 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 82 to 82. [2022-11-02 20:36:49,861 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 82 states, 63 states have (on average 1.3015873015873016) internal successors, (82), 70 states have internal predecessors, (82), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-02 20:36:49,867 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 82 states to 82 states and 105 transitions. [2022-11-02 20:36:49,869 INFO L78 Accepts]: Start accepts. Automaton has 82 states and 105 transitions. Word has length 32 [2022-11-02 20:36:49,870 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:49,870 INFO L495 AbstractCegarLoop]: Abstraction has 82 states and 105 transitions. [2022-11-02 20:36:49,872 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:36:49,872 INFO L276 IsEmpty]: Start isEmpty. Operand 82 states and 105 transitions. [2022-11-02 20:36:49,879 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-02 20:36:49,879 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:49,880 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:49,880 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-02 20:36:49,881 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:49,883 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:49,884 INFO L85 PathProgramCache]: Analyzing trace with hash 79054015, now seen corresponding path program 1 times [2022-11-02 20:36:49,885 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:49,885 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2115733722] [2022-11-02 20:36:49,885 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:49,886 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:49,935 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,124 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-11-02 20:36:50,126 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,129 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-11-02 20:36:50,134 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,137 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:50,139 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:50,139 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2115733722] [2022-11-02 20:36:50,140 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2115733722] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:50,140 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:50,141 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-02 20:36:50,141 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1378522272] [2022-11-02 20:36:50,141 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:50,143 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-02 20:36:50,144 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:50,145 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-02 20:36:50,147 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:36:50,148 INFO L87 Difference]: Start difference. First operand 82 states and 105 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:36:50,187 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:50,192 INFO L93 Difference]: Finished difference Result 128 states and 164 transitions. [2022-11-02 20:36:50,193 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-02 20:36:50,194 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-11-02 20:36:50,194 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:50,196 INFO L225 Difference]: With dead ends: 128 [2022-11-02 20:36:50,197 INFO L226 Difference]: Without dead ends: 73 [2022-11-02 20:36:50,199 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:36:50,202 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 13 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 167 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:50,205 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 167 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:36:50,206 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-11-02 20:36:50,216 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-11-02 20:36:50,217 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.3157894736842106) internal successors, (75), 64 states have internal predecessors, (75), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-02 20:36:50,218 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 93 transitions. [2022-11-02 20:36:50,218 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 93 transitions. Word has length 33 [2022-11-02 20:36:50,218 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:50,219 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 93 transitions. [2022-11-02 20:36:50,219 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-02 20:36:50,219 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 93 transitions. [2022-11-02 20:36:50,221 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-02 20:36:50,221 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:50,221 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:50,221 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-02 20:36:50,222 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:50,222 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:50,223 INFO L85 PathProgramCache]: Analyzing trace with hash 321911882, now seen corresponding path program 1 times [2022-11-02 20:36:50,223 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:50,223 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [970725329] [2022-11-02 20:36:50,223 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:50,224 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:50,249 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,457 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:50,460 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,463 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-11-02 20:36:50,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,468 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:50,469 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:50,469 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [970725329] [2022-11-02 20:36:50,469 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [970725329] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:50,470 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:50,470 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:36:50,470 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [351241768] [2022-11-02 20:36:50,471 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:50,471 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:36:50,471 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:50,472 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:36:50,472 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:36:50,473 INFO L87 Difference]: Start difference. First operand 73 states and 93 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:36:50,583 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:50,593 INFO L93 Difference]: Finished difference Result 138 states and 179 transitions. [2022-11-02 20:36:50,594 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:36:50,594 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-11-02 20:36:50,595 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:50,596 INFO L225 Difference]: With dead ends: 138 [2022-11-02 20:36:50,596 INFO L226 Difference]: Without dead ends: 73 [2022-11-02 20:36:50,597 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:36:50,599 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 116 mSDsluCounter, 138 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 116 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:50,600 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [116 Valid, 224 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:36:50,601 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-11-02 20:36:50,611 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-11-02 20:36:50,612 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-02 20:36:50,612 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 92 transitions. [2022-11-02 20:36:50,613 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 92 transitions. Word has length 38 [2022-11-02 20:36:50,614 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:50,615 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 92 transitions. [2022-11-02 20:36:50,615 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:36:50,616 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 92 transitions. [2022-11-02 20:36:50,617 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-02 20:36:50,617 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:50,618 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:50,618 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-02 20:36:50,618 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:50,619 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:50,619 INFO L85 PathProgramCache]: Analyzing trace with hash 1433797075, now seen corresponding path program 1 times [2022-11-02 20:36:50,619 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:50,620 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [410138604] [2022-11-02 20:36:50,620 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:50,620 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:50,645 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,729 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:50,731 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,735 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-11-02 20:36:50,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:50,739 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:50,739 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:50,739 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [410138604] [2022-11-02 20:36:50,740 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [410138604] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:50,740 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:50,740 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-02 20:36:50,741 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [559584864] [2022-11-02 20:36:50,741 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:50,742 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-02 20:36:50,742 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:50,742 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-02 20:36:50,743 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:36:50,743 INFO L87 Difference]: Start difference. First operand 73 states and 92 transitions. Second operand has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:36:50,786 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:50,786 INFO L93 Difference]: Finished difference Result 186 states and 241 transitions. [2022-11-02 20:36:50,787 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-02 20:36:50,787 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2022-11-02 20:36:50,787 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:50,789 INFO L225 Difference]: With dead ends: 186 [2022-11-02 20:36:50,789 INFO L226 Difference]: Without dead ends: 121 [2022-11-02 20:36:50,790 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-02 20:36:50,791 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 54 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 54 SdHoareTripleChecker+Valid, 175 SdHoareTripleChecker+Invalid, 15 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:50,792 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [54 Valid, 175 Invalid, 15 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-02 20:36:50,793 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 121 states. [2022-11-02 20:36:50,815 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 121 to 119. [2022-11-02 20:36:50,815 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 119 states, 92 states have (on average 1.2826086956521738) internal successors, (118), 99 states have internal predecessors, (118), 14 states have call successors, (14), 12 states have call predecessors, (14), 12 states have return successors, (18), 14 states have call predecessors, (18), 14 states have call successors, (18) [2022-11-02 20:36:50,816 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 119 states to 119 states and 150 transitions. [2022-11-02 20:36:50,817 INFO L78 Accepts]: Start accepts. Automaton has 119 states and 150 transitions. Word has length 44 [2022-11-02 20:36:50,817 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:50,817 INFO L495 AbstractCegarLoop]: Abstraction has 119 states and 150 transitions. [2022-11-02 20:36:50,818 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-02 20:36:50,818 INFO L276 IsEmpty]: Start isEmpty. Operand 119 states and 150 transitions. [2022-11-02 20:36:50,827 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-02 20:36:50,827 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:50,828 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:50,828 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-02 20:36:50,829 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:50,829 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:50,830 INFO L85 PathProgramCache]: Analyzing trace with hash -464428248, now seen corresponding path program 1 times [2022-11-02 20:36:50,830 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:50,830 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [39373640] [2022-11-02 20:36:50,830 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:50,831 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:50,881 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,009 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:51,014 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,018 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-02 20:36:51,026 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,062 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-02 20:36:51,064 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,069 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:51,069 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:51,070 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [39373640] [2022-11-02 20:36:51,070 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [39373640] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:51,076 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:51,076 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-02 20:36:51,076 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [807723829] [2022-11-02 20:36:51,078 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:51,078 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:36:51,078 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:51,079 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:36:51,079 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-02 20:36:51,079 INFO L87 Difference]: Start difference. First operand 119 states and 150 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:51,374 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:51,375 INFO L93 Difference]: Finished difference Result 262 states and 338 transitions. [2022-11-02 20:36:51,375 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:36:51,376 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-02 20:36:51,377 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:51,380 INFO L225 Difference]: With dead ends: 262 [2022-11-02 20:36:51,380 INFO L226 Difference]: Without dead ends: 151 [2022-11-02 20:36:51,381 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-02 20:36:51,388 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 63 mSDsluCounter, 286 mSDsCounter, 0 mSdLazyCounter, 109 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 66 SdHoareTripleChecker+Valid, 380 SdHoareTripleChecker+Invalid, 128 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 109 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:51,389 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [66 Valid, 380 Invalid, 128 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 109 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:36:51,392 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 151 states. [2022-11-02 20:36:51,426 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 151 to 146. [2022-11-02 20:36:51,428 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 146 states, 114 states have (on average 1.280701754385965) internal successors, (146), 121 states have internal predecessors, (146), 16 states have call successors, (16), 12 states have call predecessors, (16), 15 states have return successors, (23), 17 states have call predecessors, (23), 16 states have call successors, (23) [2022-11-02 20:36:51,429 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 146 states to 146 states and 185 transitions. [2022-11-02 20:36:51,429 INFO L78 Accepts]: Start accepts. Automaton has 146 states and 185 transitions. Word has length 52 [2022-11-02 20:36:51,429 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:51,429 INFO L495 AbstractCegarLoop]: Abstraction has 146 states and 185 transitions. [2022-11-02 20:36:51,430 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:51,430 INFO L276 IsEmpty]: Start isEmpty. Operand 146 states and 185 transitions. [2022-11-02 20:36:51,433 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-02 20:36:51,434 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:51,434 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:51,434 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-02 20:36:51,435 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:51,435 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:51,435 INFO L85 PathProgramCache]: Analyzing trace with hash 2141595306, now seen corresponding path program 1 times [2022-11-02 20:36:51,436 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:51,436 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [272202675] [2022-11-02 20:36:51,436 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:51,436 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:51,463 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,517 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:51,519 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,522 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-02 20:36:51,525 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,545 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-02 20:36:51,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,547 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:51,548 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:51,548 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [272202675] [2022-11-02 20:36:51,548 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [272202675] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:51,548 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:51,548 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:36:51,549 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1638754911] [2022-11-02 20:36:51,549 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:51,549 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:36:51,549 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:51,550 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:36:51,550 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:36:51,550 INFO L87 Difference]: Start difference. First operand 146 states and 185 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:51,686 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:51,686 INFO L93 Difference]: Finished difference Result 294 states and 382 transitions. [2022-11-02 20:36:51,687 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-02 20:36:51,687 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-02 20:36:51,687 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:51,689 INFO L225 Difference]: With dead ends: 294 [2022-11-02 20:36:51,689 INFO L226 Difference]: Without dead ends: 156 [2022-11-02 20:36:51,690 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:36:51,691 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 65 mSDsluCounter, 204 mSDsCounter, 0 mSdLazyCounter, 81 mSolverCounterSat, 15 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 299 SdHoareTripleChecker+Invalid, 96 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 15 IncrementalHoareTripleChecker+Valid, 81 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:51,691 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 299 Invalid, 96 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [15 Valid, 81 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:36:51,692 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 156 states. [2022-11-02 20:36:51,713 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 156 to 148. [2022-11-02 20:36:51,713 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 148 states, 116 states have (on average 1.2758620689655173) internal successors, (148), 123 states have internal predecessors, (148), 16 states have call successors, (16), 12 states have call predecessors, (16), 15 states have return successors, (23), 17 states have call predecessors, (23), 16 states have call successors, (23) [2022-11-02 20:36:51,727 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 148 states to 148 states and 187 transitions. [2022-11-02 20:36:51,728 INFO L78 Accepts]: Start accepts. Automaton has 148 states and 187 transitions. Word has length 52 [2022-11-02 20:36:51,728 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:51,728 INFO L495 AbstractCegarLoop]: Abstraction has 148 states and 187 transitions. [2022-11-02 20:36:51,728 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:51,728 INFO L276 IsEmpty]: Start isEmpty. Operand 148 states and 187 transitions. [2022-11-02 20:36:51,729 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-02 20:36:51,729 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:51,729 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:51,730 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-02 20:36:51,730 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:51,730 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:51,730 INFO L85 PathProgramCache]: Analyzing trace with hash -1730670164, now seen corresponding path program 1 times [2022-11-02 20:36:51,730 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:51,731 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [928231812] [2022-11-02 20:36:51,731 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:51,731 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:51,763 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,943 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:51,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,960 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-02 20:36:51,971 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,993 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-02 20:36:51,994 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:51,996 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:51,997 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:51,997 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [928231812] [2022-11-02 20:36:51,997 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [928231812] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:51,997 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:51,997 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-02 20:36:51,997 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [365574468] [2022-11-02 20:36:51,998 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:51,999 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-02 20:36:52,000 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:52,000 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-02 20:36:52,001 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-02 20:36:52,001 INFO L87 Difference]: Start difference. First operand 148 states and 187 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:52,315 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:52,315 INFO L93 Difference]: Finished difference Result 428 states and 559 transitions. [2022-11-02 20:36:52,316 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-02 20:36:52,316 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-02 20:36:52,317 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:52,323 INFO L225 Difference]: With dead ends: 428 [2022-11-02 20:36:52,323 INFO L226 Difference]: Without dead ends: 288 [2022-11-02 20:36:52,324 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:36:52,329 INFO L413 NwaCegarLoop]: 147 mSDtfsCounter, 209 mSDsluCounter, 168 mSDsCounter, 0 mSdLazyCounter, 150 mSolverCounterSat, 61 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 216 SdHoareTripleChecker+Valid, 315 SdHoareTripleChecker+Invalid, 211 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 61 IncrementalHoareTripleChecker+Valid, 150 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:52,333 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [216 Valid, 315 Invalid, 211 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [61 Valid, 150 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:36:52,336 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 288 states. [2022-11-02 20:36:52,403 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 288 to 280. [2022-11-02 20:36:52,406 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 280 states, 216 states have (on average 1.25) internal successors, (270), 227 states have internal predecessors, (270), 34 states have call successors, (34), 28 states have call predecessors, (34), 29 states have return successors, (53), 34 states have call predecessors, (53), 34 states have call successors, (53) [2022-11-02 20:36:52,410 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 280 states to 280 states and 357 transitions. [2022-11-02 20:36:52,411 INFO L78 Accepts]: Start accepts. Automaton has 280 states and 357 transitions. Word has length 52 [2022-11-02 20:36:52,413 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:52,413 INFO L495 AbstractCegarLoop]: Abstraction has 280 states and 357 transitions. [2022-11-02 20:36:52,414 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-02 20:36:52,416 INFO L276 IsEmpty]: Start isEmpty. Operand 280 states and 357 transitions. [2022-11-02 20:36:52,417 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2022-11-02 20:36:52,418 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:52,418 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:52,418 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-02 20:36:52,419 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:52,419 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:52,420 INFO L85 PathProgramCache]: Analyzing trace with hash 742025993, now seen corresponding path program 1 times [2022-11-02 20:36:52,420 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:52,420 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [52857338] [2022-11-02 20:36:52,420 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:52,421 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:52,457 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:52,645 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-02 20:36:52,646 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:52,657 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-02 20:36:52,660 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:52,669 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-02 20:36:52,670 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:52,677 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 46 [2022-11-02 20:36:52,680 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:52,699 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-02 20:36:52,700 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:52,700 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [52857338] [2022-11-02 20:36:52,700 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [52857338] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:52,701 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:52,701 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-02 20:36:52,701 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1683813853] [2022-11-02 20:36:52,701 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:52,702 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-02 20:36:52,702 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:52,704 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-02 20:36:52,704 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-02 20:36:52,705 INFO L87 Difference]: Start difference. First operand 280 states and 357 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-11-02 20:36:53,087 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:53,087 INFO L93 Difference]: Finished difference Result 568 states and 737 transitions. [2022-11-02 20:36:53,087 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2022-11-02 20:36:53,088 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) Word has length 54 [2022-11-02 20:36:53,088 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:53,090 INFO L225 Difference]: With dead ends: 568 [2022-11-02 20:36:53,091 INFO L226 Difference]: Without dead ends: 296 [2022-11-02 20:36:53,092 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2022-11-02 20:36:53,093 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 105 mSDsluCounter, 334 mSDsCounter, 0 mSdLazyCounter, 194 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 111 SdHoareTripleChecker+Valid, 429 SdHoareTripleChecker+Invalid, 226 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 194 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:53,093 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [111 Valid, 429 Invalid, 226 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 194 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-02 20:36:53,094 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 296 states. [2022-11-02 20:36:53,125 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 296 to 276. [2022-11-02 20:36:53,126 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 276 states, 212 states have (on average 1.2169811320754718) internal successors, (258), 223 states have internal predecessors, (258), 34 states have call successors, (34), 28 states have call predecessors, (34), 29 states have return successors, (53), 34 states have call predecessors, (53), 34 states have call successors, (53) [2022-11-02 20:36:53,128 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 276 states to 276 states and 345 transitions. [2022-11-02 20:36:53,128 INFO L78 Accepts]: Start accepts. Automaton has 276 states and 345 transitions. Word has length 54 [2022-11-02 20:36:53,129 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:53,131 INFO L495 AbstractCegarLoop]: Abstraction has 276 states and 345 transitions. [2022-11-02 20:36:53,132 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-11-02 20:36:53,132 INFO L276 IsEmpty]: Start isEmpty. Operand 276 states and 345 transitions. [2022-11-02 20:36:53,134 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2022-11-02 20:36:53,134 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:53,135 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:53,135 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-02 20:36:53,135 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:53,136 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:53,136 INFO L85 PathProgramCache]: Analyzing trace with hash -731489466, now seen corresponding path program 1 times [2022-11-02 20:36:53,136 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:53,136 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1635951620] [2022-11-02 20:36:53,137 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:53,137 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:53,160 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:53,360 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:36:53,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:53,429 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-02 20:36:53,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:53,442 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-11-02 20:36:53,445 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:53,463 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2022-11-02 20:36:53,464 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:53,466 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-02 20:36:53,466 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:53,467 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1635951620] [2022-11-02 20:36:53,467 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1635951620] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:53,467 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:53,467 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-11-02 20:36:53,467 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [238251558] [2022-11-02 20:36:53,467 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:53,469 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-11-02 20:36:53,469 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:53,469 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-11-02 20:36:53,470 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=72, Unknown=0, NotChecked=0, Total=90 [2022-11-02 20:36:53,470 INFO L87 Difference]: Start difference. First operand 276 states and 345 transitions. Second operand has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-02 20:36:54,627 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:54,627 INFO L93 Difference]: Finished difference Result 873 states and 1145 transitions. [2022-11-02 20:36:54,627 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-02 20:36:54,628 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) Word has length 56 [2022-11-02 20:36:54,628 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:54,632 INFO L225 Difference]: With dead ends: 873 [2022-11-02 20:36:54,632 INFO L226 Difference]: Without dead ends: 656 [2022-11-02 20:36:54,634 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 43 GetRequests, 10 SyntacticMatches, 1 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 262 ImplicationChecksByTransitivity, 0.4s TimeCoverageRelationStatistics Valid=215, Invalid=907, Unknown=0, NotChecked=0, Total=1122 [2022-11-02 20:36:54,635 INFO L413 NwaCegarLoop]: 162 mSDtfsCounter, 471 mSDsluCounter, 687 mSDsCounter, 0 mSdLazyCounter, 734 mSolverCounterSat, 176 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 478 SdHoareTripleChecker+Valid, 849 SdHoareTripleChecker+Invalid, 910 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 176 IncrementalHoareTripleChecker+Valid, 734 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.7s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:54,635 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [478 Valid, 849 Invalid, 910 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [176 Valid, 734 Invalid, 0 Unknown, 0 Unchecked, 0.7s Time] [2022-11-02 20:36:54,636 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 656 states. [2022-11-02 20:36:54,717 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 656 to 533. [2022-11-02 20:36:54,719 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 533 states, 410 states have (on average 1.2146341463414634) internal successors, (498), 434 states have internal predecessors, (498), 65 states have call successors, (65), 49 states have call predecessors, (65), 57 states have return successors, (104), 67 states have call predecessors, (104), 65 states have call successors, (104) [2022-11-02 20:36:54,723 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 533 states to 533 states and 667 transitions. [2022-11-02 20:36:54,724 INFO L78 Accepts]: Start accepts. Automaton has 533 states and 667 transitions. Word has length 56 [2022-11-02 20:36:54,724 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:54,724 INFO L495 AbstractCegarLoop]: Abstraction has 533 states and 667 transitions. [2022-11-02 20:36:54,725 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-02 20:36:54,725 INFO L276 IsEmpty]: Start isEmpty. Operand 533 states and 667 transitions. [2022-11-02 20:36:54,726 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2022-11-02 20:36:54,727 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:54,727 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:54,727 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-02 20:36:54,727 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:54,728 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:54,728 INFO L85 PathProgramCache]: Analyzing trace with hash -981985599, now seen corresponding path program 1 times [2022-11-02 20:36:54,728 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:54,728 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [12502461] [2022-11-02 20:36:54,729 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:54,729 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:54,753 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,012 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:36:55,013 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,029 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-02 20:36:55,033 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,054 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:55,055 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,067 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-02 20:36:55,070 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,078 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-11-02 20:36:55,095 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,111 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-11-02 20:36:55,113 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,115 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:36:55,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,117 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2022-11-02 20:36:55,118 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,121 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 18 proven. 9 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-02 20:36:55,121 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:55,121 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [12502461] [2022-11-02 20:36:55,121 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [12502461] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:36:55,122 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [918370403] [2022-11-02 20:36:55,122 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:55,122 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:36:55,122 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:36:55,127 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:36:55,135 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-02 20:36:55,279 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:55,283 INFO L263 TraceCheckSpWp]: Trace formula consists of 472 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-02 20:36:55,293 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:36:55,616 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 25 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-02 20:36:55,616 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-02 20:36:55,913 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 19 proven. 8 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-02 20:36:55,914 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [918370403] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-02 20:36:55,914 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-02 20:36:55,914 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 6, 6] total 16 [2022-11-02 20:36:55,915 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1156278565] [2022-11-02 20:36:55,915 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-02 20:36:55,915 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 16 states [2022-11-02 20:36:55,916 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:55,917 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 16 interpolants. [2022-11-02 20:36:55,917 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=38, Invalid=202, Unknown=0, NotChecked=0, Total=240 [2022-11-02 20:36:55,917 INFO L87 Difference]: Start difference. First operand 533 states and 667 transitions. Second operand has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2022-11-02 20:36:57,429 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:57,430 INFO L93 Difference]: Finished difference Result 1171 states and 1508 transitions. [2022-11-02 20:36:57,430 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2022-11-02 20:36:57,431 INFO L78 Accepts]: Start accepts. Automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) Word has length 96 [2022-11-02 20:36:57,431 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:57,435 INFO L225 Difference]: With dead ends: 1171 [2022-11-02 20:36:57,435 INFO L226 Difference]: Without dead ends: 695 [2022-11-02 20:36:57,438 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 263 GetRequests, 215 SyntacticMatches, 4 SemanticMatches, 44 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 508 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=361, Invalid=1709, Unknown=0, NotChecked=0, Total=2070 [2022-11-02 20:36:57,439 INFO L413 NwaCegarLoop]: 220 mSDtfsCounter, 431 mSDsluCounter, 1114 mSDsCounter, 0 mSdLazyCounter, 882 mSolverCounterSat, 198 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 432 SdHoareTripleChecker+Valid, 1334 SdHoareTripleChecker+Invalid, 1080 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 198 IncrementalHoareTripleChecker+Valid, 882 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:57,439 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [432 Valid, 1334 Invalid, 1080 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [198 Valid, 882 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2022-11-02 20:36:57,441 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 695 states. [2022-11-02 20:36:57,526 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 695 to 598. [2022-11-02 20:36:57,527 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 598 states, 454 states have (on average 1.2026431718061674) internal successors, (546), 486 states have internal predecessors, (546), 75 states have call successors, (75), 63 states have call predecessors, (75), 68 states have return successors, (100), 70 states have call predecessors, (100), 75 states have call successors, (100) [2022-11-02 20:36:57,531 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 598 states to 598 states and 721 transitions. [2022-11-02 20:36:57,533 INFO L78 Accepts]: Start accepts. Automaton has 598 states and 721 transitions. Word has length 96 [2022-11-02 20:36:57,534 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:57,535 INFO L495 AbstractCegarLoop]: Abstraction has 598 states and 721 transitions. [2022-11-02 20:36:57,535 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2022-11-02 20:36:57,535 INFO L276 IsEmpty]: Start isEmpty. Operand 598 states and 721 transitions. [2022-11-02 20:36:57,544 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 169 [2022-11-02 20:36:57,545 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:57,547 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:57,592 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-02 20:36:57,772 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-02 20:36:57,773 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:57,773 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:57,774 INFO L85 PathProgramCache]: Analyzing trace with hash -1684606529, now seen corresponding path program 1 times [2022-11-02 20:36:57,774 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:57,774 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1502488277] [2022-11-02 20:36:57,774 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:57,774 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:57,812 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:57,999 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:36:58,001 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,012 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-02 20:36:58,017 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,023 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:58,024 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,031 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-02 20:36:58,034 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,037 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-11-02 20:36:58,042 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,049 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:58,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,053 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-02 20:36:58,057 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,059 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:36:58,060 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,061 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2022-11-02 20:36:58,067 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,166 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:58,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,169 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 135 [2022-11-02 20:36:58,170 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,172 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 144 [2022-11-02 20:36:58,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,177 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 160 [2022-11-02 20:36:58,178 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:58,180 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 81 proven. 0 refuted. 0 times theorem prover too weak. 109 trivial. 0 not checked. [2022-11-02 20:36:58,180 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:58,180 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1502488277] [2022-11-02 20:36:58,180 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1502488277] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:36:58,181 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-02 20:36:58,181 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-11-02 20:36:58,181 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1362404443] [2022-11-02 20:36:58,181 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:36:58,182 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-11-02 20:36:58,182 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:36:58,182 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-11-02 20:36:58,183 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=69, Unknown=0, NotChecked=0, Total=90 [2022-11-02 20:36:58,183 INFO L87 Difference]: Start difference. First operand 598 states and 721 transitions. Second operand has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) [2022-11-02 20:36:59,255 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:36:59,256 INFO L93 Difference]: Finished difference Result 1713 states and 2093 transitions. [2022-11-02 20:36:59,256 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-11-02 20:36:59,256 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) Word has length 168 [2022-11-02 20:36:59,257 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:36:59,263 INFO L225 Difference]: With dead ends: 1713 [2022-11-02 20:36:59,263 INFO L226 Difference]: Without dead ends: 1123 [2022-11-02 20:36:59,265 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 62 GetRequests, 36 SyntacticMatches, 0 SemanticMatches, 26 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 150 ImplicationChecksByTransitivity, 0.4s TimeCoverageRelationStatistics Valid=178, Invalid=578, Unknown=0, NotChecked=0, Total=756 [2022-11-02 20:36:59,266 INFO L413 NwaCegarLoop]: 209 mSDtfsCounter, 484 mSDsluCounter, 519 mSDsCounter, 0 mSdLazyCounter, 514 mSolverCounterSat, 162 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 488 SdHoareTripleChecker+Valid, 728 SdHoareTripleChecker+Invalid, 676 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 162 IncrementalHoareTripleChecker+Valid, 514 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-02 20:36:59,266 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [488 Valid, 728 Invalid, 676 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [162 Valid, 514 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-02 20:36:59,268 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1123 states. [2022-11-02 20:36:59,425 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1123 to 1121. [2022-11-02 20:36:59,428 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1121 states, 849 states have (on average 1.171967020023557) internal successors, (995), 904 states have internal predecessors, (995), 143 states have call successors, (143), 122 states have call predecessors, (143), 128 states have return successors, (186), 130 states have call predecessors, (186), 143 states have call successors, (186) [2022-11-02 20:36:59,433 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1121 states to 1121 states and 1324 transitions. [2022-11-02 20:36:59,434 INFO L78 Accepts]: Start accepts. Automaton has 1121 states and 1324 transitions. Word has length 168 [2022-11-02 20:36:59,434 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:36:59,435 INFO L495 AbstractCegarLoop]: Abstraction has 1121 states and 1324 transitions. [2022-11-02 20:36:59,435 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) [2022-11-02 20:36:59,435 INFO L276 IsEmpty]: Start isEmpty. Operand 1121 states and 1324 transitions. [2022-11-02 20:36:59,440 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 173 [2022-11-02 20:36:59,441 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:36:59,441 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:36:59,441 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2022-11-02 20:36:59,441 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:36:59,442 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:36:59,442 INFO L85 PathProgramCache]: Analyzing trace with hash 734259323, now seen corresponding path program 1 times [2022-11-02 20:36:59,442 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:36:59,442 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1783932899] [2022-11-02 20:36:59,443 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:59,443 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:36:59,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,600 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:36:59,601 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,607 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-11-02 20:36:59,608 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,621 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-11-02 20:36:59,625 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,631 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:59,632 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,639 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-02 20:36:59,641 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,643 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-11-02 20:36:59,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,734 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:59,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,737 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-02 20:36:59,738 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,740 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:36:59,741 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,742 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-11-02 20:36:59,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,749 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:36:59,750 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,751 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 139 [2022-11-02 20:36:59,752 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,753 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 148 [2022-11-02 20:36:59,755 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,758 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 164 [2022-11-02 20:36:59,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,760 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 87 proven. 10 refuted. 0 times theorem prover too weak. 93 trivial. 0 not checked. [2022-11-02 20:36:59,761 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:36:59,761 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1783932899] [2022-11-02 20:36:59,761 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1783932899] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:36:59,761 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1779486260] [2022-11-02 20:36:59,761 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:36:59,762 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:36:59,762 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:36:59,767 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:36:59,778 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-02 20:36:59,938 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:36:59,941 INFO L263 TraceCheckSpWp]: Trace formula consists of 677 conjuncts, 7 conjunts are in the unsatisfiable core [2022-11-02 20:36:59,956 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:37:00,148 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 131 proven. 0 refuted. 0 times theorem prover too weak. 59 trivial. 0 not checked. [2022-11-02 20:37:00,148 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-02 20:37:00,148 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1779486260] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-02 20:37:00,148 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-02 20:37:00,149 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 15 [2022-11-02 20:37:00,149 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1805383863] [2022-11-02 20:37:00,149 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-02 20:37:00,150 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-02 20:37:00,150 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:37:00,150 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-02 20:37:00,150 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=37, Invalid=173, Unknown=0, NotChecked=0, Total=210 [2022-11-02 20:37:00,151 INFO L87 Difference]: Start difference. First operand 1121 states and 1324 transitions. Second operand has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) [2022-11-02 20:37:00,374 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:37:00,374 INFO L93 Difference]: Finished difference Result 2058 states and 2439 transitions. [2022-11-02 20:37:00,375 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-02 20:37:00,375 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) Word has length 172 [2022-11-02 20:37:00,375 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:37:00,380 INFO L225 Difference]: With dead ends: 2058 [2022-11-02 20:37:00,380 INFO L226 Difference]: Without dead ends: 1043 [2022-11-02 20:37:00,385 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 208 GetRequests, 193 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 29 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=52, Invalid=220, Unknown=0, NotChecked=0, Total=272 [2022-11-02 20:37:00,386 INFO L413 NwaCegarLoop]: 164 mSDtfsCounter, 65 mSDsluCounter, 415 mSDsCounter, 0 mSdLazyCounter, 75 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 579 SdHoareTripleChecker+Invalid, 78 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 75 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-02 20:37:00,386 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 579 Invalid, 78 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 75 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-02 20:37:00,388 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1043 states. [2022-11-02 20:37:00,527 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1043 to 1027. [2022-11-02 20:37:00,529 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1027 states, 784 states have (on average 1.1658163265306123) internal successors, (914), 830 states have internal predecessors, (914), 128 states have call successors, (128), 111 states have call predecessors, (128), 114 states have return successors, (164), 116 states have call predecessors, (164), 128 states have call successors, (164) [2022-11-02 20:37:00,534 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1027 states to 1027 states and 1206 transitions. [2022-11-02 20:37:00,535 INFO L78 Accepts]: Start accepts. Automaton has 1027 states and 1206 transitions. Word has length 172 [2022-11-02 20:37:00,536 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:37:00,536 INFO L495 AbstractCegarLoop]: Abstraction has 1027 states and 1206 transitions. [2022-11-02 20:37:00,537 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) [2022-11-02 20:37:00,537 INFO L276 IsEmpty]: Start isEmpty. Operand 1027 states and 1206 transitions. [2022-11-02 20:37:00,542 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 177 [2022-11-02 20:37:00,542 INFO L187 NwaCegarLoop]: Found error trace [2022-11-02 20:37:00,543 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:37:00,588 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-02 20:37:00,758 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:37:00,759 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-02 20:37:00,759 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-02 20:37:00,759 INFO L85 PathProgramCache]: Analyzing trace with hash 1208270879, now seen corresponding path program 1 times [2022-11-02 20:37:00,760 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-02 20:37:00,760 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1387059913] [2022-11-02 20:37:00,760 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:37:00,760 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-02 20:37:00,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,057 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-02 20:37:01,058 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,067 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-02 20:37:01,071 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,104 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:37:01,105 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,113 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-02 20:37:01,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,117 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-11-02 20:37:01,120 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,196 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:37:01,197 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,198 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-02 20:37:01,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,201 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-02 20:37:01,202 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,215 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 97 [2022-11-02 20:37:01,216 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,217 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-11-02 20:37:01,220 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,223 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-02 20:37:01,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,225 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 132 [2022-11-02 20:37:01,226 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,227 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 143 [2022-11-02 20:37:01,228 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,229 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 152 [2022-11-02 20:37:01,231 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,233 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 168 [2022-11-02 20:37:01,234 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,236 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 93 proven. 28 refuted. 0 times theorem prover too weak. 73 trivial. 0 not checked. [2022-11-02 20:37:01,236 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-02 20:37:01,236 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1387059913] [2022-11-02 20:37:01,236 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1387059913] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-02 20:37:01,237 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1700225586] [2022-11-02 20:37:01,237 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-02 20:37:01,237 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:37:01,237 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 [2022-11-02 20:37:01,238 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-02 20:37:01,259 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-02 20:37:01,419 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-02 20:37:01,422 INFO L263 TraceCheckSpWp]: Trace formula consists of 684 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-02 20:37:01,433 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-02 20:37:01,702 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 142 proven. 4 refuted. 0 times theorem prover too weak. 48 trivial. 0 not checked. [2022-11-02 20:37:01,702 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-02 20:37:02,234 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 82 proven. 42 refuted. 0 times theorem prover too weak. 70 trivial. 0 not checked. [2022-11-02 20:37:02,235 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1700225586] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-02 20:37:02,235 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-02 20:37:02,235 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 10, 11] total 26 [2022-11-02 20:37:02,238 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1720544466] [2022-11-02 20:37:02,238 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-02 20:37:02,239 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 26 states [2022-11-02 20:37:02,240 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-02 20:37:02,240 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 26 interpolants. [2022-11-02 20:37:02,241 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=123, Invalid=527, Unknown=0, NotChecked=0, Total=650 [2022-11-02 20:37:02,241 INFO L87 Difference]: Start difference. First operand 1027 states and 1206 transitions. Second operand has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) [2022-11-02 20:37:03,888 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-02 20:37:03,888 INFO L93 Difference]: Finished difference Result 2162 states and 2608 transitions. [2022-11-02 20:37:03,888 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-11-02 20:37:03,889 INFO L78 Accepts]: Start accepts. Automaton has has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) Word has length 176 [2022-11-02 20:37:03,889 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-02 20:37:03,890 INFO L225 Difference]: With dead ends: 2162 [2022-11-02 20:37:03,890 INFO L226 Difference]: Without dead ends: 0 [2022-11-02 20:37:03,897 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 428 GetRequests, 373 SyntacticMatches, 5 SemanticMatches, 50 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 530 ImplicationChecksByTransitivity, 0.8s TimeCoverageRelationStatistics Valid=549, Invalid=2103, Unknown=0, NotChecked=0, Total=2652 [2022-11-02 20:37:03,899 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 604 mSDsluCounter, 443 mSDsCounter, 0 mSdLazyCounter, 1436 mSolverCounterSat, 222 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 607 SdHoareTripleChecker+Valid, 569 SdHoareTripleChecker+Invalid, 1658 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 222 IncrementalHoareTripleChecker+Valid, 1436 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-11-02 20:37:03,899 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [607 Valid, 569 Invalid, 1658 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [222 Valid, 1436 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-11-02 20:37:03,900 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-02 20:37:03,901 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-02 20:37:03,901 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-02 20:37:03,901 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-02 20:37:03,901 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 176 [2022-11-02 20:37:03,902 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-02 20:37:03,902 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-02 20:37:03,902 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) [2022-11-02 20:37:03,902 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-02 20:37:03,903 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-02 20:37:03,906 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-02 20:37:03,947 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Ended with exit code 0 [2022-11-02 20:37:04,124 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-02 20:37:04,126 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-02 20:37:19,769 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 713 719) no Hoare annotation was computed. [2022-11-02 20:37:19,769 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 713 719) the Hoare annotation is: true [2022-11-02 20:37:19,770 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 612 623) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 0))) (.cse6 (not (<= 1 |old(~methaneLevelCritical~0)|))) (.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse5 (not (<= 1 ~pumpRunning~0))) (.cse3 (not (<= ~waterLevel~0 2))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 (not (= 2 ~waterLevel~0)) .cse2 .cse5 .cse4) (or .cse2 (not (<= 2 ~waterLevel~0)) .cse5 .cse6 .cse3 .cse4) (or .cse1 .cse2 .cse6 .cse3 .cse4) (or .cse0 .cse2 .cse5 .cse3 .cse4 (not (<= 1 ~switchedOnBeforeTS~0))))) [2022-11-02 20:37:19,770 INFO L899 garLoopResultBuilder]: For program point L616-1(lines 612 623) no Hoare annotation was computed. [2022-11-02 20:37:19,771 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 612 623) no Hoare annotation was computed. [2022-11-02 20:37:19,771 INFO L895 garLoopResultBuilder]: At program point L766(line 766) the Hoare annotation is: (let ((.cse9 (= ~pumpRunning~0 0))) (let ((.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (and .cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (not (<= 1 |old(~pumpRunning~0)|))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse4 (= 0 ~systemActive~0)) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse4) (or .cse1 .cse2 .cse3 .cse7 .cse4) (or .cse1 .cse6 .cse4 .cse8 (and .cse9 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse5 .cse3 .cse4 .cse10) (or .cse0 .cse1 .cse2 .cse6 .cse4) (or .cse5 (not (< 1 |old(~waterLevel~0)|)) .cse3 .cse4 .cse8) (or .cse5 .cse6 .cse4 .cse8 .cse10)))) [2022-11-02 20:37:19,772 INFO L895 garLoopResultBuilder]: At program point L766-1(lines 747 771) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse21 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse22 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse23 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse24 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse25 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse14 (= ~pumpRunning~0 0)) (.cse26 (<= 1 ~methaneLevelCritical~0)) (.cse15 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse27 (<= ~waterLevel~0 1)) (.cse28 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse16 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0)) (.cse18 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse11 (and .cse14 .cse26 .cse15 .cse27 .cse28 .cse16 .cse17 (not .cse4) .cse18)) (.cse13 (not (<= |old(~waterLevel~0)| 1))) (.cse20 (= ~waterLevel~0 1)) (.cse19 (not (< 1 |old(~waterLevel~0)|))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (and .cse21 .cse22 .cse15 .cse27 .cse28 .cse23 .cse24 .cse16 .cse25)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (and .cse14 .cse9)) (.cse12 (not .cse26)) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (<= 1 ~pumpRunning~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse3 (and .cse8 .cse9) .cse4 .cse10) (or .cse0 .cse11 .cse1 .cse12 .cse4 .cse5) (or .cse13 (and .cse14 .cse15 .cse9 .cse16 .cse17 .cse18) .cse11 .cse1 .cse12 .cse4 .cse5) (or .cse1 .cse19 .cse12 (and .cse14 .cse15 .cse20 .cse16 .cse17 .cse18) .cse4 .cse10) (or .cse13 .cse6 .cse7 .cse3 .cse4) (or (and .cse21 .cse22 .cse15 .cse23 .cse24 .cse20 .cse16 .cse25) .cse1 .cse19 .cse3 .cse4 .cse10) (or .cse1 .cse2 .cse3 (and .cse21 .cse22 .cse15 .cse23 .cse24 .cse9 .cse16 .cse25) .cse4 .cse10 .cse5) (or .cse6 .cse7 .cse12 .cse4 .cse10 (and .cse8 (= 2 ~waterLevel~0) .cse9))))) [2022-11-02 20:37:19,773 INFO L895 garLoopResultBuilder]: At program point L795(lines 788 798) the Hoare annotation is: (let ((.cse9 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse12 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse22 (<= 1 ~pumpRunning~0)) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse21 (<= 1 ~methaneLevelCritical~0)) (.cse8 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse23 (<= ~waterLevel~0 1)) (.cse24 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse11 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0))) (let ((.cse6 (not (< 1 |old(~waterLevel~0)|))) (.cse10 (= ~waterLevel~0 1)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse16 (not (<= 2 |old(~waterLevel~0)|))) (.cse18 (and .cse22 .cse7 .cse21 .cse8 .cse23 .cse24 .cse11 .cse17 (not .cse4))) (.cse13 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (and .cse22 .cse7 .cse8 .cse23 .cse24 .cse9 .cse11 .cse12)) (.cse19 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse20 (not (<= |old(~waterLevel~0)| 1))) (.cse14 (not (= |old(~pumpRunning~0)| 0))) (.cse15 (not .cse21))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse1 .cse6 .cse2 .cse4 (and .cse7 .cse8 .cse9 .cse10 .cse11 .cse12) .cse13) (or .cse14 .cse15 .cse4 .cse13 .cse16) (or .cse1 .cse6 .cse15 .cse4 .cse13 (and .cse7 .cse8 .cse10 .cse11 .cse17)) (or .cse0 .cse1 .cse18 .cse15 .cse4 .cse5) (or .cse14 .cse2 .cse4 .cse13 .cse16) (or (and .cse7 .cse8 .cse19 .cse11 .cse17) .cse1 .cse18 .cse15 .cse4 .cse13 .cse5) (or .cse20 .cse1 .cse2 .cse3 .cse4 (and .cse7 .cse8 .cse9 .cse19 .cse11 .cse12) .cse5) (or .cse20 .cse14 .cse2 .cse4) (or .cse20 .cse14 .cse15 .cse4)))) [2022-11-02 20:37:19,774 INFO L899 garLoopResultBuilder]: For program point L700-1(lines 700 706) no Hoare annotation was computed. [2022-11-02 20:37:19,774 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 686 712) no Hoare annotation was computed. [2022-11-02 20:37:19,774 INFO L895 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse11 (and .cse15 .cse13 .cse14)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (and (<= 1 ~pumpRunning~0) .cse15 .cse13 (< 1 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (and (= ~pumpRunning~0 0) .cse13 .cse14)) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse2 .cse4) (or .cse6 .cse8 .cse9 .cse10 .cse4) (or .cse0 .cse2 .cse4 .cse5 .cse11 .cse12) (or .cse6 .cse7 .cse8 .cse9 .cse4) (or .cse7 .cse0 .cse9 .cse4 .cse11 .cse12) (or .cse0 .cse1 .cse3 .cse9 .cse4 .cse5) (or .cse6 .cse8 .cse2 .cse10 .cse4)))) [2022-11-02 20:37:19,775 INFO L899 garLoopResultBuilder]: For program point L693(lines 693 699) no Hoare annotation was computed. [2022-11-02 20:37:19,775 INFO L899 garLoopResultBuilder]: For program point L181-1(line 181) no Hoare annotation was computed. [2022-11-02 20:37:19,775 INFO L899 garLoopResultBuilder]: For program point L693-2(lines 689 711) no Hoare annotation was computed. [2022-11-02 20:37:19,776 INFO L899 garLoopResultBuilder]: For program point L755(lines 755 763) no Hoare annotation was computed. [2022-11-02 20:37:19,776 INFO L899 garLoopResultBuilder]: For program point L751(lines 751 768) no Hoare annotation was computed. [2022-11-02 20:37:19,776 INFO L899 garLoopResultBuilder]: For program point L198(lines 198 208) no Hoare annotation was computed. [2022-11-02 20:37:19,776 INFO L899 garLoopResultBuilder]: For program point L194(lines 194 211) no Hoare annotation was computed. [2022-11-02 20:37:19,777 INFO L895 garLoopResultBuilder]: At program point L194-1(lines 186 214) the Hoare annotation is: (let ((.cse12 (= 0 ~systemActive~0))) (let ((.cse26 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse27 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse28 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse29 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse25 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse19 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse32 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse30 (<= ~waterLevel~0 1)) (.cse31 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse6 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| ~waterLevel~0)) (.cse8 (<= 1 ~switchedOnBeforeTS~0)) (.cse9 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse10 (not .cse12)) (.cse11 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse14 (not (= |old(~waterLevel~0)| 1))) (.cse15 (and .cse3 .cse4 .cse32 .cse5 .cse30 .cse31 .cse6 .cse8 .cse9 .cse10 .cse11)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse7 (= ~waterLevel~0 1)) (.cse20 (not (= |old(~pumpRunning~0)| 0))) (.cse24 (and .cse25 .cse3 .cse4 .cse6 .cse19 .cse10)) (.cse2 (not .cse32)) (.cse21 (<= 1 ~pumpRunning~0)) (.cse17 (and .cse25 .cse4 .cse26 .cse5 .cse30 .cse31 .cse27 .cse28 .cse6 .cse8 .cse29 .cse10)) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse18 (not (= ~methaneLevelCritical~0 0))) (.cse13 (not (<= |old(~waterLevel~0)| 2))) (.cse16 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5 .cse6 .cse7 .cse8 .cse9 .cse10 .cse11) .cse12 .cse13) (or .cse14 .cse0 .cse2 .cse15 .cse12 .cse16) (or .cse17 .cse14 .cse0 .cse18 .cse12 .cse16) (or (and .cse3 .cse4 .cse5 .cse6 .cse19 .cse8 .cse9 .cse10 .cse11) .cse0 .cse2 .cse15 .cse12 .cse13 .cse16) (let ((.cse22 (= 2 |timeShift_getWaterLevel_#res#1|)) (.cse23 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| 2))) (or .cse20 (and .cse21 .cse22 .cse23 .cse19) (and .cse3 .cse22 .cse23 .cse19) .cse18 .cse12 .cse13 (not (<= 2 |old(~waterLevel~0)|)))) (or (not (<= |old(~waterLevel~0)| 1)) .cse20 .cse24 .cse18 .cse12) (or .cse0 .cse1 .cse18 .cse12 .cse13 (and .cse25 .cse4 .cse26 .cse5 .cse27 .cse28 .cse6 .cse7 .cse8 .cse29 .cse10)) (or .cse20 .cse24 .cse2 .cse12 .cse13 (and .cse21 .cse4 (<= 2 ~waterLevel~0) .cse6 .cse19)) (or .cse17 .cse0 .cse18 .cse12 .cse13 (and .cse25 .cse4 .cse26 .cse5 .cse27 .cse28 .cse6 .cse19 .cse8 .cse29 .cse10) .cse16))))) [2022-11-02 20:37:19,778 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-11-02 20:37:19,779 INFO L895 garLoopResultBuilder]: At program point L661(lines 656 664) the Hoare annotation is: (let ((.cse23 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse8 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse10 (= 0 ~systemActive~0)) (.cse9 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|)) (.cse29 (<= 1 ~methaneLevelCritical~0)) (.cse15 (<= 1 ~pumpRunning~0)) (.cse19 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse28 (= ~methaneLevelCritical~0 0)) (.cse20 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse5 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse30 (<= ~waterLevel~0 1)) (.cse31 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse21 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse22 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse7 (<= 1 ~switchedOnBeforeTS~0)) (.cse24 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse18 (and .cse15 .cse19 .cse4 .cse28 .cse20 .cse5 .cse30 .cse31 .cse21 .cse22 .cse7 .cse24)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (= ~waterLevel~0 1)) (.cse16 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not .cse29)) (.cse25 (and .cse3 .cse4 .cse29 .cse5 .cse30 .cse31 .cse7 .cse8 (not .cse10) .cse9)) (.cse17 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse12 (not (= |old(~pumpRunning~0)| 0))) (.cse27 (= 2 ~waterLevel~0)) (.cse26 (and .cse3 .cse4 .cse23)) (.cse13 (not .cse28)) (.cse11 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5 .cse6 .cse7 .cse8 .cse9) .cse10 .cse11) (let ((.cse14 (= 2 |timeShift_getWaterLevel_#res#1|))) (or .cse12 .cse13 .cse10 .cse11 (and .cse3 .cse14) (and .cse15 .cse14) (not (<= 2 |old(~waterLevel~0)|)))) (or .cse16 .cse0 .cse13 .cse10 .cse17 .cse18) (or .cse0 .cse13 .cse10 .cse11 (and .cse19 .cse4 .cse20 .cse5 .cse21 .cse22 .cse23 .cse7 .cse24) .cse17 .cse18) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and .cse3 .cse4 .cse5 .cse23 .cse7 .cse8 .cse9) .cse2 .cse10 .cse25 .cse17) (or .cse12 .cse26 .cse2 .cse10 .cse11 (and .cse15 .cse4 .cse27 .cse23)) (or .cse0 .cse1 .cse13 (and .cse19 .cse4 .cse20 .cse5 .cse21 .cse22 .cse6 .cse7 .cse24) .cse10 .cse11) (or .cse16 .cse0 .cse2 .cse10 .cse25 .cse17) (or .cse12 (and .cse27 .cse23) .cse26 .cse13 .cse10 .cse11)))) [2022-11-02 20:37:19,779 INFO L895 garLoopResultBuilder]: At program point L785(lines 780 787) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse15 (<= 1 ~methaneLevelCritical~0)) (.cse11 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse12 (<= 1 ~switchedOnBeforeTS~0)) (.cse13 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse2 (= 0 ~systemActive~0)) (.cse14 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse7 (and .cse10 .cse15 .cse11 (<= ~waterLevel~0 1) (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|) .cse12 .cse13 (not .cse2) .cse14)) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse9 (not (<= |old(~waterLevel~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not .cse15))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2)) .cse2) (or .cse3 .cse4 .cse2 .cse5 .cse6) (or (not (= |old(~waterLevel~0)| 1)) .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse9 (and .cse10 .cse11 (= |old(~waterLevel~0)| ~waterLevel~0) .cse12 .cse13 .cse14) .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse3 .cse1 .cse2 .cse5 .cse6) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) .cse4 (and .cse10 .cse11 (= ~waterLevel~0 1) .cse12 .cse13 .cse14) .cse2 .cse5) (or .cse9 .cse3 .cse1 .cse2) (or .cse0 .cse1 .cse2 .cse5 .cse8) (or .cse9 .cse3 .cse4 .cse2)))) [2022-11-02 20:37:19,780 INFO L899 garLoopResultBuilder]: For program point L199(lines 199 205) no Hoare annotation was computed. [2022-11-02 20:37:19,780 INFO L895 garLoopResultBuilder]: At program point L761(line 761) the Hoare annotation is: (let ((.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse12 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse13 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse14 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse15 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse16 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse10 (not (< 1 |old(~waterLevel~0)|))) (.cse9 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (and .cse11 .cse12 .cse13 (<= ~waterLevel~0 1) (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|) .cse14 .cse15 .cse16 .cse17)) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= 0 ~systemActive~0)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse8) (or .cse9 .cse0 .cse6 .cse3 .cse4) (or .cse5 .cse2 .cse3 .cse7 .cse8) (or .cse0 .cse10 .cse6 .cse3 .cse7) (or (and .cse11 .cse12 .cse13 .cse14 .cse15 (= ~waterLevel~0 1) .cse16 .cse17) .cse0 .cse10 .cse2 .cse3 .cse7) (or .cse9 .cse5 .cse2 .cse3) (or .cse9 .cse5 .cse6 .cse3) (or .cse0 .cse1 .cse2 (and .cse11 .cse12 .cse13 .cse14 .cse15 (= |old(~waterLevel~0)| ~waterLevel~0) .cse16 .cse17) .cse3 .cse7 .cse4)))) [2022-11-02 20:37:19,781 INFO L895 garLoopResultBuilder]: At program point L183(lines 176 185) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 0)) (.cse14 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse17 (<= 1 ~switchedOnBeforeTS~0))) (let ((.cse5 (and .cse14 .cse16 .cse17)) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse12 (and (<= 1 ~pumpRunning~0) .cse14 .cse16 .cse17)) (.cse6 (not (<= 1 |old(~pumpRunning~0)|))) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (and .cse15 .cse16)) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (and .cse14 .cse15 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse11 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse6 .cse7 .cse4 .cse8) (or .cse0 .cse5 .cse6 .cse3 .cse4 .cse8) (or .cse1 .cse9 .cse7 .cse4 .cse10 .cse11) (or .cse12 .cse6 .cse3 .cse13 .cse4) (or .cse12 .cse6 .cse7 .cse13 .cse4) (or .cse0 .cse1 .cse2 .cse7 .cse4) (or .cse1 .cse9 .cse3 .cse4 .cse10 .cse11)))) [2022-11-02 20:37:19,781 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2)) .cse2) (or .cse3 .cse4 .cse2 .cse5 .cse6) (or .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse3 .cse1 .cse2 .cse5 .cse6) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) .cse4 .cse2 .cse5) (or .cse7 .cse3 .cse1 .cse2) (or .cse0 .cse1 .cse2 .cse5 .cse8) (or .cse7 .cse3 .cse4 .cse2))) [2022-11-02 20:37:19,782 INFO L895 garLoopResultBuilder]: At program point L629(lines 624 632) the Hoare annotation is: (let ((.cse15 (<= 1 ~methaneLevelCritical~0)) (.cse4 (= 0 ~systemActive~0)) (.cse17 (<= 1 ~pumpRunning~0)) (.cse16 (= ~methaneLevelCritical~0 0)) (.cse20 (<= ~waterLevel~0 1)) (.cse21 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse18 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse19 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse22 (<= 1 ~switchedOnBeforeTS~0))) (let ((.cse10 (not (< 1 |old(~waterLevel~0)|))) (.cse11 (and .cse18 .cse19 (= ~waterLevel~0 1) .cse22)) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse13 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (and .cse18 .cse19 (= |old(~waterLevel~0)| ~waterLevel~0) .cse22)) (.cse9 (and .cse17 .cse18 .cse16 .cse19 .cse20 .cse21 .cse22)) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (and .cse17 .cse18 .cse15 .cse19 .cse20 .cse21 .cse22 (not .cse4))) (.cse6 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not .cse16)) (.cse14 (not (<= |old(~waterLevel~0)| 1))) (.cse12 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not .cse15))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (or .cse7 .cse1 .cse8 .cse9 .cse4 .cse6) (or .cse1 .cse10 .cse8 .cse11 .cse4 .cse5) (or .cse12 .cse3 .cse4 .cse5 .cse13) (or .cse1 .cse10 .cse3 .cse11 .cse4 .cse5) (or .cse12 .cse8 .cse4 .cse5 .cse13) (or .cse14 .cse0 .cse1 .cse8 .cse9 .cse4 .cse6) (or .cse7 .cse1 .cse2 .cse3 .cse4 .cse6) (or .cse14 .cse12 .cse8 .cse4) (or .cse14 .cse12 .cse3 .cse4)))) [2022-11-02 20:37:19,782 INFO L899 garLoopResultBuilder]: For program point L592(lines 592 596) no Hoare annotation was computed. [2022-11-02 20:37:19,782 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 686 712) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse11 (and .cse15 .cse13 .cse14)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (and (<= 1 ~pumpRunning~0) .cse15 .cse13 (< 1 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (and (= ~pumpRunning~0 0) .cse13 .cse14)) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse2 .cse4) (or .cse6 .cse8 .cse9 .cse10 .cse4) (or .cse0 .cse2 .cse4 .cse5 .cse11 .cse12) (or .cse6 .cse7 .cse8 .cse9 .cse4) (or .cse7 .cse0 .cse9 .cse4 .cse11 .cse12) (or .cse0 .cse1 .cse3 .cse9 .cse4 .cse5) (or .cse6 .cse8 .cse2 .cse10 .cse4)))) [2022-11-02 20:37:19,783 INFO L895 garLoopResultBuilder]: At program point L592-2(lines 588 599) the Hoare annotation is: (let ((.cse18 (= ~methaneLevelCritical~0 0)) (.cse19 (<= 1 ~pumpRunning~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse17 (<= 1 ~methaneLevelCritical~0)) (.cse20 (<= ~waterLevel~0 1)) (.cse21 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= 0 ~systemActive~0))) (let ((.cse11 (and .cse19 .cse3 .cse17 .cse20 .cse21 .cse5 (not .cse6))) (.cse13 (and .cse3 .cse20 (= |old(~waterLevel~0)| ~waterLevel~0) .cse5)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse4 (= ~waterLevel~0 1)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse9 (not (<= 2 |old(~waterLevel~0)|))) (.cse10 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse16 (and .cse19 .cse3 .cse18 .cse20 .cse21 .cse5)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse15 (not .cse18)) (.cse14 (not (<= |old(~waterLevel~0)| 1))) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse17))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5) .cse6 .cse7) (or .cse8 .cse2 .cse6 .cse7 .cse9) (or .cse10 .cse0 .cse2 .cse6 .cse11 .cse12) (or .cse13 .cse0 .cse2 .cse6 .cse7 .cse11 .cse12) (or .cse14 .cse13 .cse0 .cse15 .cse16 .cse6 .cse12) (or .cse0 .cse1 .cse15 .cse6 .cse4 .cse7) (or .cse0 .cse15 .cse16 (not (= |old(~waterLevel~0)| 2)) .cse6) (or .cse8 .cse15 .cse6 .cse7 .cse9) (or .cse10 .cse0 .cse15 .cse16 .cse6 .cse12) (or .cse14 .cse8 .cse15 .cse6) (or .cse14 .cse8 .cse2 .cse6)))) [2022-11-02 20:37:19,783 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 686 712) no Hoare annotation was computed. [2022-11-02 20:37:19,784 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-02 20:37:19,784 INFO L895 garLoopResultBuilder]: At program point L196(line 196) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse12 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0)) (.cse13 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|)) (.cse26 (<= 1 ~methaneLevelCritical~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse7 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse28 (= ~methaneLevelCritical~0 0)) (.cse16 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse8 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse25 (<= ~waterLevel~0 1)) (.cse27 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse17 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse18 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse9 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| ~waterLevel~0)) (.cse11 (<= 1 ~switchedOnBeforeTS~0)) (.cse19 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse22 (not (< 1 |old(~waterLevel~0)|))) (.cse23 (= ~waterLevel~0 1)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse21 (and (<= 1 ~pumpRunning~0) .cse15 .cse7 .cse28 .cse16 .cse8 .cse25 .cse27 .cse17 .cse18 .cse9 .cse11 .cse19)) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse24 (not (= |old(~pumpRunning~0)| 0))) (.cse20 (not .cse28)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse14 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not .cse26)) (.cse3 (and .cse6 .cse7 .cse26 .cse8 .cse25 .cse27 .cse9 .cse11 .cse12 (not .cse4) .cse13))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or (and .cse6 .cse7 .cse8 .cse9 .cse10 .cse11 .cse12 .cse13) .cse1 .cse2 .cse3 .cse4 .cse14 .cse5) (or (and .cse15 .cse7 .cse16 .cse8 .cse17 .cse18 .cse9 .cse10 .cse11 .cse19) .cse1 .cse20 .cse21 .cse4 .cse14 .cse5) (or .cse1 .cse22 .cse20 .cse4 .cse14 (and .cse15 .cse7 .cse16 .cse8 .cse17 .cse18 .cse9 .cse23 .cse11 .cse19)) (or .cse24 .cse2 .cse4 .cse14 (not (<= 2 |old(~waterLevel~0)|))) (or .cse1 .cse22 .cse2 .cse4 .cse23 .cse14) (or .cse0 .cse1 .cse20 .cse21 .cse4 .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse24 .cse2 .cse4 (and .cse6 .cse7 .cse9 .cse10)) (or .cse24 .cse20 (and .cse6 .cse7 .cse25 .cse9 .cse10) .cse4 .cse14) (or .cse1 .cse2 .cse3 (not (= |old(~waterLevel~0)| 2)) .cse4)))) [2022-11-02 20:37:19,784 INFO L899 garLoopResultBuilder]: For program point L196-1(line 196) no Hoare annotation was computed. [2022-11-02 20:37:19,785 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 61 90) no Hoare annotation was computed. [2022-11-02 20:37:19,785 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 61 90) the Hoare annotation is: true [2022-11-02 20:37:19,785 INFO L902 garLoopResultBuilder]: At program point L86(lines 61 90) the Hoare annotation is: true [2022-11-02 20:37:19,785 INFO L899 garLoopResultBuilder]: For program point L82(line 82) no Hoare annotation was computed. [2022-11-02 20:37:19,785 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 79) no Hoare annotation was computed. [2022-11-02 20:37:19,786 INFO L902 garLoopResultBuilder]: At program point L75-1(lines 75 79) the Hoare annotation is: true [2022-11-02 20:37:19,786 INFO L899 garLoopResultBuilder]: For program point L72(line 72) no Hoare annotation was computed. [2022-11-02 20:37:19,786 INFO L902 garLoopResultBuilder]: At program point L71-2(lines 71 85) the Hoare annotation is: true [2022-11-02 20:37:19,786 INFO L902 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: true [2022-11-02 20:37:19,786 INFO L899 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2022-11-02 20:37:19,786 INFO L899 garLoopResultBuilder]: For program point L927(lines 927 933) no Hoare annotation was computed. [2022-11-02 20:37:19,787 INFO L895 garLoopResultBuilder]: At program point L894(lines 890 896) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-02 20:37:19,787 INFO L899 garLoopResultBuilder]: For program point L927-1(lines 927 933) no Hoare annotation was computed. [2022-11-02 20:37:19,787 INFO L895 garLoopResultBuilder]: At program point L122(lines 118 124) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-02 20:37:19,787 INFO L899 garLoopResultBuilder]: For program point L151(lines 151 158) no Hoare annotation was computed. [2022-11-02 20:37:19,787 INFO L899 garLoopResultBuilder]: For program point L919(lines 919 923) no Hoare annotation was computed. [2022-11-02 20:37:19,787 INFO L899 garLoopResultBuilder]: For program point L151-2(lines 151 158) no Hoare annotation was computed. [2022-11-02 20:37:19,788 INFO L902 garLoopResultBuilder]: At program point L135(lines 127 137) the Hoare annotation is: true [2022-11-02 20:37:19,788 INFO L895 garLoopResultBuilder]: At program point L965(lines 916 966) the Hoare annotation is: false [2022-11-02 20:37:19,788 INFO L902 garLoopResultBuilder]: At program point L160(lines 141 163) the Hoare annotation is: true [2022-11-02 20:37:19,788 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-02 20:37:19,788 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-02 20:37:19,788 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-02 20:37:19,789 INFO L895 garLoopResultBuilder]: At program point L887(lines 883 889) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-02 20:37:19,789 INFO L895 garLoopResultBuilder]: At program point L173(lines 168 175) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-02 20:37:19,789 INFO L899 garLoopResultBuilder]: For program point L937(lines 937 943) no Hoare annotation was computed. [2022-11-02 20:37:19,789 INFO L899 garLoopResultBuilder]: For program point L937-1(lines 937 943) no Hoare annotation was computed. [2022-11-02 20:37:19,790 INFO L895 garLoopResultBuilder]: At program point L962(lines 917 964) the Hoare annotation is: (let ((.cse7 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 1)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6))) [2022-11-02 20:37:19,790 INFO L895 garLoopResultBuilder]: At program point L929(line 929) the Hoare annotation is: (let ((.cse7 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 1)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6))) [2022-11-02 20:37:19,790 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-02 20:37:19,790 INFO L895 garLoopResultBuilder]: At program point L868(lines 863 870) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse9 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7) (and .cse0 .cse8 .cse9 .cse2 .cse3 .cse4 .cse7) (and .cse10 .cse9 .cse2 .cse3 .cse4 .cse5 .cse7) (and .cse10 .cse1 .cse2 .cse3 (<= ~waterLevel~0 1) .cse4 .cse7) (and .cse10 .cse1 .cse8 .cse2 .cse3 .cse4 .cse7) (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) .cse4 .cse5 .cse7) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7))) [2022-11-02 20:37:19,791 INFO L899 garLoopResultBuilder]: For program point L955(lines 955 959) no Hoare annotation was computed. [2022-11-02 20:37:19,791 INFO L895 garLoopResultBuilder]: At program point L955-2(lines 947 960) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse9 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7) (and .cse0 .cse8 .cse9 .cse2 .cse3 .cse4 .cse7) (and .cse10 .cse9 .cse2 .cse3 .cse4 .cse5 .cse7) (and .cse10 .cse1 .cse2 .cse3 (<= ~waterLevel~0 1) .cse4 .cse7) (and .cse10 .cse1 .cse8 .cse2 .cse3 .cse4 .cse7) (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) .cse4 .cse5 .cse7) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7))) [2022-11-02 20:37:19,791 INFO L899 garLoopResultBuilder]: For program point L918(lines 917 964) no Hoare annotation was computed. [2022-11-02 20:37:19,791 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 960) no Hoare annotation was computed. [2022-11-02 20:37:19,792 INFO L895 garLoopResultBuilder]: At program point L939(line 939) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse1 (= 2 ~waterLevel~0)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse4 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse8 (<= ~waterLevel~0 2)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse2 .cse3 .cse4 .cse5 .cse8 .cse6) (and .cse7 .cse9 .cse3 .cse4 (<= ~waterLevel~0 1) .cse5 .cse6) (and .cse7 .cse9 .cse1 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse3 .cse4 (<= 2 ~waterLevel~0) .cse5 .cse8 .cse6) (and .cse0 .cse2 .cse3 .cse4 .cse5 .cse8 (<= 1 ~switchedOnBeforeTS~0) .cse6))) [2022-11-02 20:37:19,792 INFO L902 garLoopResultBuilder]: At program point L968(lines 907 972) the Hoare annotation is: true [2022-11-02 20:37:19,792 INFO L895 garLoopResultBuilder]: At program point L902(lines 897 905) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-02 20:37:19,792 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 721 745) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (<= ~waterLevel~0 2))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse2 .cse3) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|)) .cse4 (not (<= ~waterLevel~0 1)) .cse3 (not (<= 1 ~switchedOnBeforeTS~0))))) [2022-11-02 20:37:19,793 INFO L895 garLoopResultBuilder]: At program point L735(line 735) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0) (not .cse3)))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) .cse1 .cse2 .cse3) (or (not (<= 1 |old(~pumpRunning~0)|)) .cse4 (not (<= ~waterLevel~0 1)) .cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 .cse4 .cse1 .cse2 .cse3)))) [2022-11-02 20:37:19,793 INFO L899 garLoopResultBuilder]: For program point L669(lines 669 675) no Hoare annotation was computed. [2022-11-02 20:37:19,793 INFO L895 garLoopResultBuilder]: At program point L859(lines 844 862) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0))) (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (and .cse6 (= 2 ~waterLevel~0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (<= ~waterLevel~0 2))) (.cse5 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse6 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (<= 1 |old(~pumpRunning~0)|)) .cse0 (not (<= ~waterLevel~0 1)) .cse1 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse2 .cse3 (not (<= 1 ~methaneLevelCritical~0)) .cse4 .cse5 .cse1) (or .cse2 .cse3 .cse0 .cse4 .cse5 .cse1)))) [2022-11-02 20:37:19,793 INFO L899 garLoopResultBuilder]: For program point L729(lines 729 737) no Hoare annotation was computed. [2022-11-02 20:37:19,793 INFO L899 garLoopResultBuilder]: For program point L725(lines 725 742) no Hoare annotation was computed. [2022-11-02 20:37:19,794 INFO L899 garLoopResultBuilder]: For program point L853(lines 853 857) no Hoare annotation was computed. [2022-11-02 20:37:19,794 INFO L899 garLoopResultBuilder]: For program point L853-2(lines 853 857) no Hoare annotation was computed. [2022-11-02 20:37:19,794 INFO L895 garLoopResultBuilder]: At program point L777(lines 772 779) the Hoare annotation is: (let ((.cse1 (not (<= ~waterLevel~0 1))) (.cse4 (<= 1 ~pumpRunning~0)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= ~waterLevel~0 2))) (.cse2 (= 0 ~systemActive~0))) (and (or (not (<= 1 |old(~pumpRunning~0)|)) .cse0 .cse1 .cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse3 .cse0 .cse1 .cse2) (or .cse3 (and .cse4 (= 2 ~waterLevel~0)) (not (<= 1 ~methaneLevelCritical~0)) .cse5 .cse2) (or .cse4 .cse3 .cse0 .cse5 .cse2))) [2022-11-02 20:37:19,794 INFO L895 garLoopResultBuilder]: At program point L740(line 740) the Hoare annotation is: (let ((.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|)) .cse0 (not (<= ~waterLevel~0 1)) .cse1 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse2 .cse0 .cse3 .cse1) (or .cse2 (not (<= 1 ~methaneLevelCritical~0)) .cse3 .cse1))) [2022-11-02 20:37:19,795 INFO L899 garLoopResultBuilder]: For program point L740-1(lines 721 745) no Hoare annotation was computed. [2022-11-02 20:37:19,795 INFO L895 garLoopResultBuilder]: At program point L674(lines 665 678) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (<= ~waterLevel~0 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1))) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= ~waterLevel~0 2))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse2 .cse6 .cse4) (or (not (<= 1 |old(~pumpRunning~0)|)) .cse7 .cse3 .cse4 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 .cse1 (and .cse5 (= 2 ~waterLevel~0)) .cse7 .cse6 .cse4)))) [2022-11-02 20:37:19,795 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 721 745) no Hoare annotation was computed. [2022-11-02 20:37:19,795 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 600 611) no Hoare annotation was computed. [2022-11-02 20:37:19,795 INFO L899 garLoopResultBuilder]: For program point L604-1(lines 600 611) no Hoare annotation was computed. [2022-11-02 20:37:19,796 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 600 611) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= 1 ~pumpRunning~0))) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse2 .cse3) (or (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse6 .cse2 .cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse1 .cse6 .cse7 .cse2 .cse3))) [2022-11-02 20:37:19,796 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 799 807) no Hoare annotation was computed. [2022-11-02 20:37:19,796 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 799 807) the Hoare annotation is: true [2022-11-02 20:37:19,796 INFO L899 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 799 807) no Hoare annotation was computed. [2022-11-02 20:37:19,799 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-02 20:37:19,802 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-02 20:37:19,852 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 02.11 08:37:19 BoogieIcfgContainer [2022-11-02 20:37:19,852 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-02 20:37:19,853 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-02 20:37:19,853 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-02 20:37:19,853 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-02 20:37:19,854 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 02.11 08:36:48" (3/4) ... [2022-11-02 20:37:19,857 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-02 20:37:19,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-02 20:37:19,864 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-02 20:37:19,864 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-02 20:37:19,864 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-02 20:37:19,865 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-02 20:37:19,865 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-02 20:37:19,865 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-02 20:37:19,877 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2022-11-02 20:37:19,878 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-02 20:37:19,879 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-02 20:37:19,879 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-02 20:37:19,880 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-02 20:37:19,880 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:37:19,881 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-02 20:37:19,910 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-02 20:37:19,911 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-02 20:37:19,911 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-02 20:37:19,911 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) [2022-11-02 20:37:19,913 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-02 20:37:19,914 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && (((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-02 20:37:19,914 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) [2022-11-02 20:37:19,915 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(pumpRunning) == 0) || (((1 <= pumpRunning && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || (((pumpRunning == 0 && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)))) && (((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && waterLevel == \result) && 2 <= waterLevel) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS))) [2022-11-02 20:37:19,916 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) || !(1 <= \old(pumpRunning))) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((!(1 <= \old(pumpRunning)) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || (((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && 2 == waterLevel) && \old(waterLevel) == waterLevel)) [2022-11-02 20:37:19,916 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-02 20:37:19,917 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 2 == \result)) || (1 <= pumpRunning && 2 == \result)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= pumpRunning && waterLevel == \result) && 2 == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-02 20:37:19,917 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-02 20:37:19,918 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-02 20:37:19,918 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) [2022-11-02 20:37:19,919 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-02 20:37:19,919 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive) [2022-11-02 20:37:19,919 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || (1 <= pumpRunning && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((1 <= pumpRunning || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) [2022-11-02 20:37:19,960 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/witness.graphml [2022-11-02 20:37:19,960 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-02 20:37:19,961 INFO L158 Benchmark]: Toolchain (without parser) took 32516.03ms. Allocated memory was 96.5MB in the beginning and 264.2MB in the end (delta: 167.8MB). Free memory was 58.5MB in the beginning and 122.0MB in the end (delta: -63.4MB). Peak memory consumption was 103.7MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,961 INFO L158 Benchmark]: CDTParser took 0.36ms. Allocated memory is still 96.5MB. Free memory was 75.6MB in the beginning and 75.5MB in the end (delta: 100.8kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-02 20:37:19,962 INFO L158 Benchmark]: CACSL2BoogieTranslator took 677.63ms. Allocated memory is still 96.5MB. Free memory was 58.3MB in the beginning and 64.3MB in the end (delta: -6.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,962 INFO L158 Benchmark]: Boogie Procedure Inliner took 85.84ms. Allocated memory is still 96.5MB. Free memory was 64.3MB in the beginning and 61.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,963 INFO L158 Benchmark]: Boogie Preprocessor took 36.39ms. Allocated memory is still 96.5MB. Free memory was 61.8MB in the beginning and 60.2MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,963 INFO L158 Benchmark]: RCFGBuilder took 713.08ms. Allocated memory is still 96.5MB. Free memory was 60.2MB in the beginning and 41.3MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,964 INFO L158 Benchmark]: TraceAbstraction took 30887.53ms. Allocated memory was 96.5MB in the beginning and 264.2MB in the end (delta: 167.8MB). Free memory was 40.9MB in the beginning and 128.3MB in the end (delta: -87.4MB). Peak memory consumption was 131.4MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,965 INFO L158 Benchmark]: Witness Printer took 107.37ms. Allocated memory is still 264.2MB. Free memory was 128.3MB in the beginning and 122.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-02 20:37:19,967 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.36ms. Allocated memory is still 96.5MB. Free memory was 75.6MB in the beginning and 75.5MB in the end (delta: 100.8kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 677.63ms. Allocated memory is still 96.5MB. Free memory was 58.3MB in the beginning and 64.3MB in the end (delta: -6.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 85.84ms. Allocated memory is still 96.5MB. Free memory was 64.3MB in the beginning and 61.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 36.39ms. Allocated memory is still 96.5MB. Free memory was 61.8MB in the beginning and 60.2MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 713.08ms. Allocated memory is still 96.5MB. Free memory was 60.2MB in the beginning and 41.3MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 30887.53ms. Allocated memory was 96.5MB in the beginning and 264.2MB in the end (delta: 167.8MB). Free memory was 40.9MB in the beginning and 128.3MB in the end (delta: -87.4MB). Peak memory consumption was 131.4MB. Max. memory is 16.1GB. * Witness Printer took 107.37ms. Allocated memory is still 264.2MB. Free memory was 128.3MB in the beginning and 122.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 91 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 30.7s, OverallIterations: 13, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 7.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 15.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2718 SdHoareTripleChecker+Valid, 4.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2680 mSDsluCounter, 6162 SdHoareTripleChecker+Invalid, 3.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 4447 mSDsCounter, 903 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4194 IncrementalHoareTripleChecker+Invalid, 5097 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 903 mSolverCounterUnsat, 1715 mSDtfsCounter, 4194 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1105 GetRequests, 890 SyntacticMatches, 10 SemanticMatches, 205 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1508 ImplicationChecksByTransitivity, 2.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1121occurred in iteration=11, InterpolantAutomatonStates: 172, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.8s AutomataMinimizationTime, 13 MinimizatonAttempts, 281 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 43 LocationsWithAnnotation, 2728 PreInvPairs, 3176 NumberOfFragments, 6246 HoareAnnotationTreeSize, 2728 FomulaSimplifications, 5383 FormulaSimplificationTreeSizeReduction, 1.5s HoareSimplificationTime, 43 FomulaSimplificationsInter, 45342 FormulaSimplificationTreeSizeReductionInter, 14.0s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.6s SatisfiabilityAnalysisTime, 4.9s InterpolantComputationTime, 1469 NumberOfCodeBlocks, 1469 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 1723 ConstructedInterpolants, 0 QuantifiedInterpolants, 3477 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1833 ConjunctsInSsa, 28 ConjunctsInUnsatCore, 18 InterpolantComputations, 11 PerfectInterpolantSequences, 1171/1281 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 588]: Loop Invariant Derived loop invariant: ((((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && (((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 780]: Loop Invariant Derived loop invariant: ((((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 788]: Loop Invariant Derived loop invariant: (((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 176]: Loop Invariant Derived loop invariant: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 186]: Loop Invariant Derived loop invariant: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(pumpRunning) == 0) || (((1 <= pumpRunning && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || (((pumpRunning == 0 && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)))) && (((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && waterLevel == \result) && 2 <= waterLevel) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 916]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 907]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 118]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 61]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 656]: Loop Invariant Derived loop invariant: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 2 == \result)) || (1 <= pumpRunning && 2 == \result)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= pumpRunning && waterLevel == \result) && 2 == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 883]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 168]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 141]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 747]: Loop Invariant Derived loop invariant: ((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) || !(1 <= \old(pumpRunning))) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((!(1 <= \old(pumpRunning)) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || (((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && 2 == waterLevel) && \old(waterLevel) == waterLevel)) - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: (((((((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 772]: Loop Invariant Derived loop invariant: ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || (1 <= pumpRunning && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((1 <= pumpRunning || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) - InvariantResult [Line: 863]: Loop Invariant Derived loop invariant: ((((((((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) - InvariantResult [Line: 897]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 665]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: (((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 890]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 624]: Loop Invariant Derived loop invariant: (((((((((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 844]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive) RESULT: Ultimate proved your program to be correct! [2022-11-02 20:37:20,068 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a56d5e96-e897-42f1-936e-190e95c16201/bin/uautomizer-Dbtcem3rbc/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE