./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash a7cd784867b5981272ba60caba7961cbaf680a952b35b095dbec7935be0f5966 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 12:19:30,016 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 12:19:30,018 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 12:19:30,049 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 12:19:30,050 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 12:19:30,051 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 12:19:30,052 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 12:19:30,054 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 12:19:30,056 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 12:19:30,057 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 12:19:30,058 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 12:19:30,059 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 12:19:30,060 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 12:19:30,061 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 12:19:30,062 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 12:19:30,063 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 12:19:30,064 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 12:19:30,065 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 12:19:30,067 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 12:19:30,069 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 12:19:30,070 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 12:19:30,072 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 12:19:30,073 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 12:19:30,074 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 12:19:30,078 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 12:19:30,078 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 12:19:30,079 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 12:19:30,080 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 12:19:30,080 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 12:19:30,081 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 12:19:30,081 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 12:19:30,082 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 12:19:30,083 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 12:19:30,084 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 12:19:30,089 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 12:19:30,090 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 12:19:30,091 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 12:19:30,091 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 12:19:30,092 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 12:19:30,093 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 12:19:30,093 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 12:19:30,097 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 12:19:30,130 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 12:19:30,131 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 12:19:30,131 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 12:19:30,132 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 12:19:30,133 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 12:19:30,133 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 12:19:30,134 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 12:19:30,134 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 12:19:30,134 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 12:19:30,135 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 12:19:30,136 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 12:19:30,136 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 12:19:30,136 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 12:19:30,137 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 12:19:30,137 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 12:19:30,137 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 12:19:30,138 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 12:19:30,138 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 12:19:30,138 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 12:19:30,139 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 12:19:30,139 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 12:19:30,139 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 12:19:30,139 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 12:19:30,140 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 12:19:30,140 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 12:19:30,140 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 12:19:30,142 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 12:19:30,142 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 12:19:30,143 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 12:19:30,143 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 12:19:30,143 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 12:19:30,143 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 12:19:30,144 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 12:19:30,144 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> a7cd784867b5981272ba60caba7961cbaf680a952b35b095dbec7935be0f5966 [2022-11-16 12:19:30,432 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 12:19:30,462 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 12:19:30,464 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 12:19:30,476 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 12:19:30,477 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 12:19:30,479 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c [2022-11-16 12:19:30,555 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/data/4d414c9e7/f58716d666fd46a6b5048cd86d7e1019/FLAG4376ebc62 [2022-11-16 12:19:31,082 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 12:19:31,083 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c [2022-11-16 12:19:31,094 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/data/4d414c9e7/f58716d666fd46a6b5048cd86d7e1019/FLAG4376ebc62 [2022-11-16 12:19:31,404 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/data/4d414c9e7/f58716d666fd46a6b5048cd86d7e1019 [2022-11-16 12:19:31,407 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 12:19:31,409 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 12:19:31,410 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 12:19:31,411 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 12:19:31,416 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 12:19:31,417 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 12:19:31" (1/1) ... [2022-11-16 12:19:31,418 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@457d2ca6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:31, skipping insertion in model container [2022-11-16 12:19:31,418 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 12:19:31" (1/1) ... [2022-11-16 12:19:31,426 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 12:19:31,488 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 12:19:31,740 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c[1605,1618] [2022-11-16 12:19:31,927 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 12:19:31,936 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 12:19:31,949 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/sv-benchmarks/c/product-lines/minepump_spec1_product20.cil.c[1605,1618] [2022-11-16 12:19:32,033 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 12:19:32,058 INFO L208 MainTranslator]: Completed translation [2022-11-16 12:19:32,059 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32 WrapperNode [2022-11-16 12:19:32,059 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 12:19:32,060 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 12:19:32,060 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 12:19:32,060 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 12:19:32,074 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,088 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,127 INFO L138 Inliner]: procedures = 54, calls = 152, calls flagged for inlining = 20, calls inlined = 17, statements flattened = 219 [2022-11-16 12:19:32,127 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 12:19:32,128 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 12:19:32,128 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 12:19:32,128 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 12:19:32,142 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,143 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,145 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,145 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,150 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,159 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,162 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,175 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,178 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 12:19:32,179 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 12:19:32,179 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 12:19:32,179 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 12:19:32,180 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (1/1) ... [2022-11-16 12:19:32,192 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 12:19:32,207 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 12:19:32,224 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 12:19:32,256 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 12:19:32,279 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 12:19:32,279 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 12:19:32,279 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 12:19:32,279 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-16 12:19:32,279 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-16 12:19:32,279 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 12:19:32,279 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 12:19:32,280 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 12:19:32,280 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 12:19:32,280 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 12:19:32,280 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 12:19:32,280 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-16 12:19:32,280 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-16 12:19:32,280 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 12:19:32,280 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 12:19:32,281 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 12:19:32,281 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 12:19:32,281 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 12:19:32,369 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 12:19:32,371 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 12:19:32,665 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 12:19:32,672 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 12:19:32,683 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 12:19:32,686 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:19:32 BoogieIcfgContainer [2022-11-16 12:19:32,686 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 12:19:32,689 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 12:19:32,689 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 12:19:32,693 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 12:19:32,693 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 12:19:31" (1/3) ... [2022-11-16 12:19:32,694 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@177a3929 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 12:19:32, skipping insertion in model container [2022-11-16 12:19:32,707 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:19:32" (2/3) ... [2022-11-16 12:19:32,707 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@177a3929 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 12:19:32, skipping insertion in model container [2022-11-16 12:19:32,707 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:19:32" (3/3) ... [2022-11-16 12:19:32,709 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product20.cil.c [2022-11-16 12:19:32,733 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 12:19:32,733 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 12:19:32,802 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 12:19:32,808 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4b2d3e54, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 12:19:32,808 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 12:19:32,812 INFO L276 IsEmpty]: Start isEmpty. Operand has 81 states, 61 states have (on average 1.3770491803278688) internal successors, (84), 68 states have internal predecessors, (84), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 12:19:32,821 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2022-11-16 12:19:32,822 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:19:32,822 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:19:32,823 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:19:32,831 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:19:32,833 INFO L85 PathProgramCache]: Analyzing trace with hash 253223704, now seen corresponding path program 1 times [2022-11-16 12:19:32,843 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:19:32,843 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2065809629] [2022-11-16 12:19:32,843 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:19:32,845 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:19:33,001 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,139 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-11-16 12:19:33,143 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,159 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 12:19:33,160 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:19:33,160 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2065809629] [2022-11-16 12:19:33,161 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2065809629] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:19:33,162 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:19:33,163 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 12:19:33,164 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [764397676] [2022-11-16 12:19:33,166 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:19:33,171 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 12:19:33,172 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:19:33,207 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 12:19:33,208 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 12:19:33,211 INFO L87 Difference]: Start difference. First operand has 81 states, 61 states have (on average 1.3770491803278688) internal successors, (84), 68 states have internal predecessors, (84), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,261 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:19:33,261 INFO L93 Difference]: Finished difference Result 154 states and 207 transitions. [2022-11-16 12:19:33,262 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 12:19:33,263 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2022-11-16 12:19:33,264 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:19:33,282 INFO L225 Difference]: With dead ends: 154 [2022-11-16 12:19:33,282 INFO L226 Difference]: Without dead ends: 72 [2022-11-16 12:19:33,286 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 12:19:33,289 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 100 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:19:33,290 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 100 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:19:33,307 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 72 states. [2022-11-16 12:19:33,350 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 72 to 72. [2022-11-16 12:19:33,351 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 72 states, 54 states have (on average 1.2962962962962963) internal successors, (70), 60 states have internal predecessors, (70), 11 states have call successors, (11), 7 states have call predecessors, (11), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2022-11-16 12:19:33,353 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 72 states to 72 states and 91 transitions. [2022-11-16 12:19:33,354 INFO L78 Accepts]: Start accepts. Automaton has 72 states and 91 transitions. Word has length 23 [2022-11-16 12:19:33,355 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:19:33,355 INFO L495 AbstractCegarLoop]: Abstraction has 72 states and 91 transitions. [2022-11-16 12:19:33,355 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,356 INFO L276 IsEmpty]: Start isEmpty. Operand 72 states and 91 transitions. [2022-11-16 12:19:33,358 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-16 12:19:33,358 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:19:33,358 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:19:33,359 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 12:19:33,359 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:19:33,360 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:19:33,360 INFO L85 PathProgramCache]: Analyzing trace with hash 981629421, now seen corresponding path program 1 times [2022-11-16 12:19:33,360 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:19:33,361 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1465073044] [2022-11-16 12:19:33,361 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:19:33,361 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:19:33,417 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,595 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-16 12:19:33,602 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,604 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 12:19:33,605 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:19:33,605 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1465073044] [2022-11-16 12:19:33,605 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1465073044] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:19:33,605 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:19:33,605 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 12:19:33,606 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [20626492] [2022-11-16 12:19:33,606 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:19:33,607 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 12:19:33,607 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:19:33,608 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 12:19:33,608 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:19:33,609 INFO L87 Difference]: Start difference. First operand 72 states and 91 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,642 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:19:33,642 INFO L93 Difference]: Finished difference Result 105 states and 131 transitions. [2022-11-16 12:19:33,647 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 12:19:33,648 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2022-11-16 12:19:33,651 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:19:33,653 INFO L225 Difference]: With dead ends: 105 [2022-11-16 12:19:33,653 INFO L226 Difference]: Without dead ends: 63 [2022-11-16 12:19:33,654 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:19:33,655 INFO L413 NwaCegarLoop]: 78 mSDtfsCounter, 17 mSDsluCounter, 56 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 134 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:19:33,656 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 134 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:19:33,657 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 63 states. [2022-11-16 12:19:33,670 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 63 to 63. [2022-11-16 12:19:33,671 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 63 states, 48 states have (on average 1.3125) internal successors, (63), 54 states have internal predecessors, (63), 8 states have call successors, (8), 6 states have call predecessors, (8), 6 states have return successors, (8), 6 states have call predecessors, (8), 8 states have call successors, (8) [2022-11-16 12:19:33,680 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 63 states to 63 states and 79 transitions. [2022-11-16 12:19:33,681 INFO L78 Accepts]: Start accepts. Automaton has 63 states and 79 transitions. Word has length 24 [2022-11-16 12:19:33,681 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:19:33,682 INFO L495 AbstractCegarLoop]: Abstraction has 63 states and 79 transitions. [2022-11-16 12:19:33,683 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,683 INFO L276 IsEmpty]: Start isEmpty. Operand 63 states and 79 transitions. [2022-11-16 12:19:33,685 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2022-11-16 12:19:33,685 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:19:33,685 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:19:33,685 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 12:19:33,686 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:19:33,687 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:19:33,687 INFO L85 PathProgramCache]: Analyzing trace with hash 826577867, now seen corresponding path program 1 times [2022-11-16 12:19:33,688 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:19:33,689 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1323167497] [2022-11-16 12:19:33,689 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:19:33,690 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:19:33,730 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,836 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 12:19:33,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:33,839 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 12:19:33,840 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:19:33,840 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1323167497] [2022-11-16 12:19:33,840 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1323167497] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:19:33,840 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:19:33,840 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 12:19:33,841 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [621232033] [2022-11-16 12:19:33,841 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:19:33,841 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 12:19:33,842 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:19:33,842 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 12:19:33,842 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 12:19:33,842 INFO L87 Difference]: Start difference. First operand 63 states and 79 transitions. Second operand has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,942 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:19:33,942 INFO L93 Difference]: Finished difference Result 161 states and 206 transitions. [2022-11-16 12:19:33,942 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-16 12:19:33,943 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2022-11-16 12:19:33,943 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:19:33,945 INFO L225 Difference]: With dead ends: 161 [2022-11-16 12:19:33,945 INFO L226 Difference]: Without dead ends: 105 [2022-11-16 12:19:33,946 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-16 12:19:33,947 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 142 mSDsluCounter, 182 mSDsCounter, 0 mSdLazyCounter, 12 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 142 SdHoareTripleChecker+Valid, 273 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 12 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:19:33,947 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [142 Valid, 273 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 12 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:19:33,948 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 105 states. [2022-11-16 12:19:33,971 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 105 to 102. [2022-11-16 12:19:33,973 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 102 states, 77 states have (on average 1.3376623376623376) internal successors, (103), 86 states have internal predecessors, (103), 13 states have call successors, (13), 11 states have call predecessors, (13), 11 states have return successors, (14), 10 states have call predecessors, (14), 13 states have call successors, (14) [2022-11-16 12:19:33,980 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 102 states to 102 states and 130 transitions. [2022-11-16 12:19:33,982 INFO L78 Accepts]: Start accepts. Automaton has 102 states and 130 transitions. Word has length 29 [2022-11-16 12:19:33,982 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:19:33,983 INFO L495 AbstractCegarLoop]: Abstraction has 102 states and 130 transitions. [2022-11-16 12:19:33,983 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:33,983 INFO L276 IsEmpty]: Start isEmpty. Operand 102 states and 130 transitions. [2022-11-16 12:19:33,984 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-16 12:19:33,987 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:19:33,987 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:19:33,987 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 12:19:33,988 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:19:33,988 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:19:33,989 INFO L85 PathProgramCache]: Analyzing trace with hash -166090445, now seen corresponding path program 1 times [2022-11-16 12:19:33,990 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:19:33,990 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1070539295] [2022-11-16 12:19:33,990 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:19:33,990 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:19:34,032 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:34,165 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 12:19:34,167 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:19:34,170 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 12:19:34,171 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:19:34,171 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1070539295] [2022-11-16 12:19:34,171 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1070539295] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:19:34,171 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:19:34,171 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 12:19:34,172 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1084931721] [2022-11-16 12:19:34,172 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:19:34,172 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 12:19:34,173 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:19:34,173 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 12:19:34,173 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 12:19:34,173 INFO L87 Difference]: Start difference. First operand 102 states and 130 transitions. Second operand has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:34,245 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:19:34,249 INFO L93 Difference]: Finished difference Result 182 states and 237 transitions. [2022-11-16 12:19:34,250 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 12:19:34,250 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-11-16 12:19:34,250 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:19:34,251 INFO L225 Difference]: With dead ends: 182 [2022-11-16 12:19:34,251 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 12:19:34,252 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-16 12:19:34,257 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 38 mSDsluCounter, 101 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 154 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:19:34,257 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [38 Valid, 154 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:19:34,258 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 12:19:34,261 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 12:19:34,261 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 12:19:34,262 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 12:19:34,262 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 32 [2022-11-16 12:19:34,262 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:19:34,262 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 12:19:34,263 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 12:19:34,263 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 12:19:34,263 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 12:19:34,265 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 12:19:34,267 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 12:19:34,269 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 12:19:34,649 INFO L902 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 310 317) the Hoare annotation is: true [2022-11-16 12:19:34,650 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 310 317) no Hoare annotation was computed. [2022-11-16 12:19:34,650 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 310 317) no Hoare annotation was computed. [2022-11-16 12:19:34,650 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 269 275) no Hoare annotation was computed. [2022-11-16 12:19:34,651 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 269 275) the Hoare annotation is: true [2022-11-16 12:19:34,651 INFO L899 garLoopResultBuilder]: For program point L448-1(lines 444 455) no Hoare annotation was computed. [2022-11-16 12:19:34,651 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 444 455) the Hoare annotation is: true [2022-11-16 12:19:34,651 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 444 455) no Hoare annotation was computed. [2022-11-16 12:19:34,651 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 456 464) the Hoare annotation is: true [2022-11-16 12:19:34,651 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 456 464) no Hoare annotation was computed. [2022-11-16 12:19:34,652 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 456 464) no Hoare annotation was computed. [2022-11-16 12:19:34,652 INFO L895 garLoopResultBuilder]: At program point L287(line 287) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,653 INFO L895 garLoopResultBuilder]: At program point L502(lines 497 505) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,653 INFO L899 garLoopResultBuilder]: For program point L424(lines 424 428) no Hoare annotation was computed. [2022-11-16 12:19:34,653 INFO L895 garLoopResultBuilder]: At program point L296(line 296) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0)))) [2022-11-16 12:19:34,656 INFO L895 garLoopResultBuilder]: At program point L296-1(lines 277 301) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0)))) [2022-11-16 12:19:34,659 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 245 268) no Hoare annotation was computed. [2022-11-16 12:19:34,660 INFO L895 garLoopResultBuilder]: At program point L424-2(lines 420 431) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,660 INFO L899 garLoopResultBuilder]: For program point L383(lines 383 387) no Hoare annotation was computed. [2022-11-16 12:19:34,661 INFO L899 garLoopResultBuilder]: For program point L383-2(lines 383 387) no Hoare annotation was computed. [2022-11-16 12:19:34,661 INFO L899 garLoopResultBuilder]: For program point L920(lines 920 926) no Hoare annotation was computed. [2022-11-16 12:19:34,661 INFO L899 garLoopResultBuilder]: For program point L916(lines 916 929) no Hoare annotation was computed. [2022-11-16 12:19:34,662 INFO L895 garLoopResultBuilder]: At program point L916-1(lines 908 932) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-16 12:19:34,663 INFO L895 garLoopResultBuilder]: At program point L334(lines 329 337) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (= |timeShift_isPumpRunning_#res#1| 0))) [2022-11-16 12:19:34,663 INFO L899 garLoopResultBuilder]: For program point L256-1(lines 256 262) no Hoare annotation was computed. [2022-11-16 12:19:34,665 INFO L899 garLoopResultBuilder]: For program point L285(lines 285 293) no Hoare annotation was computed. [2022-11-16 12:19:34,665 INFO L899 garLoopResultBuilder]: For program point L281(lines 281 298) no Hoare annotation was computed. [2022-11-16 12:19:34,665 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-11-16 12:19:34,665 INFO L895 garLoopResultBuilder]: At program point L389(lines 374 392) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,665 INFO L899 garLoopResultBuilder]: For program point L249-1(lines 248 267) no Hoare annotation was computed. [2022-11-16 12:19:34,665 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,666 INFO L895 garLoopResultBuilder]: At program point L914(line 914) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-16 12:19:34,666 INFO L899 garLoopResultBuilder]: For program point L914-1(line 914) no Hoare annotation was computed. [2022-11-16 12:19:34,666 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 245 268) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-16 12:19:34,666 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 245 268) no Hoare annotation was computed. [2022-11-16 12:19:34,666 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-16 12:19:34,667 INFO L895 garLoopResultBuilder]: At program point L291(line 291) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-16 12:19:34,667 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 61 90) no Hoare annotation was computed. [2022-11-16 12:19:34,670 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 61 90) the Hoare annotation is: true [2022-11-16 12:19:34,670 INFO L902 garLoopResultBuilder]: At program point L86(lines 61 90) the Hoare annotation is: true [2022-11-16 12:19:34,670 INFO L899 garLoopResultBuilder]: For program point L82(line 82) no Hoare annotation was computed. [2022-11-16 12:19:34,670 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 79) no Hoare annotation was computed. [2022-11-16 12:19:34,670 INFO L902 garLoopResultBuilder]: At program point L75-1(lines 75 79) the Hoare annotation is: true [2022-11-16 12:19:34,671 INFO L899 garLoopResultBuilder]: For program point L72(line 72) no Hoare annotation was computed. [2022-11-16 12:19:34,671 INFO L902 garLoopResultBuilder]: At program point L71-2(lines 71 85) the Hoare annotation is: true [2022-11-16 12:19:34,671 INFO L902 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: true [2022-11-16 12:19:34,671 INFO L899 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2022-11-16 12:19:34,671 INFO L895 garLoopResultBuilder]: At program point L225(lines 174 226) the Hoare annotation is: false [2022-11-16 12:19:34,671 INFO L895 garLoopResultBuilder]: At program point L122(lines 118 124) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:19:34,671 INFO L899 garLoopResultBuilder]: For program point L213(lines 213 219) no Hoare annotation was computed. [2022-11-16 12:19:34,672 INFO L895 garLoopResultBuilder]: At program point L213-2(lines 205 220) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-16 12:19:34,672 INFO L899 garLoopResultBuilder]: For program point L176(lines 175 224) no Hoare annotation was computed. [2022-11-16 12:19:34,672 INFO L895 garLoopResultBuilder]: At program point L399(line 399) the Hoare annotation is: false [2022-11-16 12:19:34,672 INFO L899 garLoopResultBuilder]: For program point L205(lines 205 220) no Hoare annotation was computed. [2022-11-16 12:19:34,672 INFO L895 garLoopResultBuilder]: At program point L903(lines 898 906) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:19:34,672 INFO L895 garLoopResultBuilder]: At program point L197(line 197) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-16 12:19:34,672 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 12:19:34,673 INFO L895 garLoopResultBuilder]: At program point L895(lines 891 897) the Hoare annotation is: (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0))) [2022-11-16 12:19:34,674 INFO L895 garLoopResultBuilder]: At program point L222(lines 175 224) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point L185(lines 185 191) no Hoare annotation was computed. [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point L185-1(lines 185 191) no Hoare annotation was computed. [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point L177(lines 177 181) no Hoare annotation was computed. [2022-11-16 12:19:34,674 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 12:19:34,675 INFO L895 garLoopResultBuilder]: At program point L413(lines 408 415) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-11-16 12:19:34,675 INFO L895 garLoopResultBuilder]: At program point L888(lines 884 890) the Hoare annotation is: (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0))) [2022-11-16 12:19:34,675 INFO L899 garLoopResultBuilder]: For program point L149(lines 149 156) no Hoare annotation was computed. [2022-11-16 12:19:34,675 INFO L895 garLoopResultBuilder]: At program point L405(lines 393 407) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-16 12:19:34,675 INFO L899 garLoopResultBuilder]: For program point L149-2(lines 149 156) no Hoare annotation was computed. [2022-11-16 12:19:34,675 INFO L899 garLoopResultBuilder]: For program point L397(lines 397 403) no Hoare annotation was computed. [2022-11-16 12:19:34,675 INFO L899 garLoopResultBuilder]: For program point L397-1(lines 397 403) no Hoare annotation was computed. [2022-11-16 12:19:34,676 INFO L902 garLoopResultBuilder]: At program point L133(lines 126 135) the Hoare annotation is: true [2022-11-16 12:19:34,676 INFO L902 garLoopResultBuilder]: At program point L228(lines 165 232) the Hoare annotation is: true [2022-11-16 12:19:34,676 INFO L899 garLoopResultBuilder]: For program point L195(lines 195 201) no Hoare annotation was computed. [2022-11-16 12:19:34,676 INFO L899 garLoopResultBuilder]: For program point L195-1(lines 195 201) no Hoare annotation was computed. [2022-11-16 12:19:34,677 INFO L902 garLoopResultBuilder]: At program point L158(lines 139 161) the Hoare annotation is: true [2022-11-16 12:19:34,677 INFO L895 garLoopResultBuilder]: At program point L187(line 187) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-16 12:19:34,677 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 432 443) no Hoare annotation was computed. [2022-11-16 12:19:34,677 INFO L902 garLoopResultBuilder]: At program point waterRiseENTRY(lines 432 443) the Hoare annotation is: true [2022-11-16 12:19:34,677 INFO L899 garLoopResultBuilder]: For program point L436-1(lines 432 443) no Hoare annotation was computed. [2022-11-16 12:19:34,681 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-11-16 12:19:34,683 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 12:19:34,724 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 12:19:34 BoogieIcfgContainer [2022-11-16 12:19:34,724 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 12:19:34,725 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 12:19:34,725 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 12:19:34,725 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 12:19:34,726 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:19:32" (3/4) ... [2022-11-16 12:19:34,738 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 12:19:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-16 12:19:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 12:19:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 12:19:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-16 12:19:34,746 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 12:19:34,746 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 12:19:34,746 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 12:19:34,760 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 49 nodes and edges [2022-11-16 12:19:34,761 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 12:19:34,761 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 12:19:34,761 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 12:19:34,762 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 12:19:34,762 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 12:19:34,762 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 12:19:34,791 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && \result == 1) && !(0 == systemActive) [2022-11-16 12:19:34,792 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && \result == 1) && tmp == 1) && !(0 == systemActive) [2022-11-16 12:19:34,793 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0 [2022-11-16 12:19:34,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-16 12:19:34,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(0 == systemActive)) [2022-11-16 12:19:34,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || pumpRunning == 0 [2022-11-16 12:19:34,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive) [2022-11-16 12:19:34,798 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0 [2022-11-16 12:19:34,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0) [2022-11-16 12:19:34,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-16 12:19:34,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-16 12:19:34,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-16 12:19:34,835 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 12:19:34,835 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 12:19:34,836 INFO L158 Benchmark]: Toolchain (without parser) took 3426.95ms. Allocated memory was 127.9MB in the beginning and 155.2MB in the end (delta: 27.3MB). Free memory was 90.3MB in the beginning and 110.9MB in the end (delta: -20.6MB). Peak memory consumption was 6.4MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,836 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 127.9MB. Free memory is still 107.6MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 12:19:34,837 INFO L158 Benchmark]: CACSL2BoogieTranslator took 648.99ms. Allocated memory is still 127.9MB. Free memory was 90.0MB in the beginning and 92.7MB in the end (delta: -2.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,837 INFO L158 Benchmark]: Boogie Procedure Inliner took 67.35ms. Allocated memory is still 127.9MB. Free memory was 92.7MB in the beginning and 90.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,837 INFO L158 Benchmark]: Boogie Preprocessor took 49.91ms. Allocated memory is still 127.9MB. Free memory was 90.6MB in the beginning and 89.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,837 INFO L158 Benchmark]: RCFGBuilder took 507.78ms. Allocated memory is still 127.9MB. Free memory was 88.5MB in the beginning and 71.0MB in the end (delta: 17.5MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,838 INFO L158 Benchmark]: TraceAbstraction took 2035.71ms. Allocated memory was 127.9MB in the beginning and 155.2MB in the end (delta: 27.3MB). Free memory was 70.5MB in the beginning and 116.1MB in the end (delta: -45.7MB). Peak memory consumption was 44.5MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,838 INFO L158 Benchmark]: Witness Printer took 110.01ms. Allocated memory is still 155.2MB. Free memory was 116.1MB in the beginning and 110.9MB in the end (delta: 5.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 12:19:34,843 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 127.9MB. Free memory is still 107.6MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 648.99ms. Allocated memory is still 127.9MB. Free memory was 90.0MB in the beginning and 92.7MB in the end (delta: -2.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 67.35ms. Allocated memory is still 127.9MB. Free memory was 92.7MB in the beginning and 90.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 49.91ms. Allocated memory is still 127.9MB. Free memory was 90.6MB in the beginning and 89.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 507.78ms. Allocated memory is still 127.9MB. Free memory was 88.5MB in the beginning and 71.0MB in the end (delta: 17.5MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 2035.71ms. Allocated memory was 127.9MB in the beginning and 155.2MB in the end (delta: 27.3MB). Free memory was 70.5MB in the beginning and 116.1MB in the end (delta: -45.7MB). Peak memory consumption was 44.5MB. Max. memory is 16.1GB. * Witness Printer took 110.01ms. Allocated memory is still 155.2MB. Free memory was 116.1MB in the beginning and 110.9MB in the end (delta: 5.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 81 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 1.9s, OverallIterations: 4, TraceHistogramMax: 1, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 0.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.4s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 201 SdHoareTripleChecker+Valid, 0.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 197 mSDsluCounter, 661 SdHoareTripleChecker+Invalid, 0.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 339 mSDsCounter, 24 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 27 IncrementalHoareTripleChecker+Invalid, 51 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 24 mSolverCounterUnsat, 322 mSDtfsCounter, 27 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 31 GetRequests, 19 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=102occurred in iteration=3, InterpolantAutomatonStates: 16, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 3 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 37 LocationsWithAnnotation, 181 PreInvPairs, 211 NumberOfFragments, 224 HoareAnnotationTreeSize, 181 FomulaSimplifications, 42 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 37 FomulaSimplificationsInter, 316 FormulaSimplificationTreeSizeReductionInter, 0.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.6s InterpolantComputationTime, 108 NumberOfCodeBlocks, 108 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 104 ConstructedInterpolants, 0 QuantifiedInterpolants, 178 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 0/0 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 898]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && \result == 1) && !(0 == systemActive) - InvariantResult [Line: 374]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 165]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 884]: Loop Invariant Derived loop invariant: pumpRunning == 0 && !(0 == systemActive) - InvariantResult [Line: 277]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(0 == systemActive)) - InvariantResult [Line: 329]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0) - InvariantResult [Line: 174]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 908]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || pumpRunning == 0 - InvariantResult [Line: 408]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive) - InvariantResult [Line: 420]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 126]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 891]: Loop Invariant Derived loop invariant: pumpRunning == 0 && !(0 == systemActive) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 497]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 393]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0 - InvariantResult [Line: 139]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 118]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && \result == 1) && tmp == 1) && !(0 == systemActive) - InvariantResult [Line: 61]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 175]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0 RESULT: Ultimate proved your program to be correct! [2022-11-16 12:19:34,887 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f5272e7d-f657-42ff-83f7-4cf19f2be2c8/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE