./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash e91d5c860cfea17112af53939b2fffb1e4c536355098377ab18c754994d1bc2b --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 10:58:49,555 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 10:58:49,557 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 10:58:49,584 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 10:58:49,585 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 10:58:49,588 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 10:58:49,591 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 10:58:49,597 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 10:58:49,599 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 10:58:49,606 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 10:58:49,608 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 10:58:49,609 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 10:58:49,610 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 10:58:49,613 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 10:58:49,614 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 10:58:49,616 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 10:58:49,618 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 10:58:49,619 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 10:58:49,620 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 10:58:49,626 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 10:58:49,628 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 10:58:49,630 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 10:58:49,633 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 10:58:49,634 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 10:58:49,639 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 10:58:49,644 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 10:58:49,645 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 10:58:49,646 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 10:58:49,647 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 10:58:49,648 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 10:58:49,649 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 10:58:49,650 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 10:58:49,651 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 10:58:49,652 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 10:58:49,654 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 10:58:49,655 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 10:58:49,655 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 10:58:49,656 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 10:58:49,656 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 10:58:49,657 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 10:58:49,657 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 10:58:49,658 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 10:58:49,697 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 10:58:49,697 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 10:58:49,697 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 10:58:49,698 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 10:58:49,698 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 10:58:49,699 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 10:58:49,699 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 10:58:49,699 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 10:58:49,700 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 10:58:49,700 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 10:58:49,700 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 10:58:49,701 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 10:58:49,701 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 10:58:49,701 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 10:58:49,701 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 10:58:49,702 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 10:58:49,702 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 10:58:49,702 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 10:58:49,702 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 10:58:49,702 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 10:58:49,703 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 10:58:49,703 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 10:58:49,703 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 10:58:49,704 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 10:58:49,704 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 10:58:49,704 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 10:58:49,704 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 10:58:49,705 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 10:58:49,705 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 10:58:49,705 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 10:58:49,705 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 10:58:49,706 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 10:58:49,706 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 10:58:49,706 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> e91d5c860cfea17112af53939b2fffb1e4c536355098377ab18c754994d1bc2b [2022-11-16 10:58:50,001 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 10:58:50,029 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 10:58:50,034 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 10:58:50,036 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 10:58:50,036 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 10:58:50,038 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c [2022-11-16 10:58:50,124 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/data/17ef2a5f9/de527fa0e69c4d4cb05d5f69f8ebf654/FLAG33b8f7909 [2022-11-16 10:58:50,664 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 10:58:50,665 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c [2022-11-16 10:58:50,680 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/data/17ef2a5f9/de527fa0e69c4d4cb05d5f69f8ebf654/FLAG33b8f7909 [2022-11-16 10:58:50,975 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/data/17ef2a5f9/de527fa0e69c4d4cb05d5f69f8ebf654 [2022-11-16 10:58:50,977 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 10:58:50,978 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 10:58:50,980 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 10:58:50,980 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 10:58:50,992 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 10:58:50,993 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 10:58:50" (1/1) ... [2022-11-16 10:58:50,994 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@519ad48d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:50, skipping insertion in model container [2022-11-16 10:58:50,994 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 10:58:50" (1/1) ... [2022-11-16 10:58:51,010 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 10:58:51,064 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 10:58:51,455 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c[15987,16000] [2022-11-16 10:58:51,472 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 10:58:51,481 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 10:58:51,540 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/sv-benchmarks/c/product-lines/minepump_spec4_product53.cil.c[15987,16000] [2022-11-16 10:58:51,550 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 10:58:51,567 INFO L208 MainTranslator]: Completed translation [2022-11-16 10:58:51,568 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51 WrapperNode [2022-11-16 10:58:51,568 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 10:58:51,569 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 10:58:51,569 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 10:58:51,570 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 10:58:51,577 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,590 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,631 INFO L138 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 281 [2022-11-16 10:58:51,632 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 10:58:51,633 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 10:58:51,633 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 10:58:51,633 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 10:58:51,642 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,643 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,655 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,665 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,670 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,674 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,688 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,689 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,691 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 10:58:51,692 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 10:58:51,692 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 10:58:51,693 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 10:58:51,700 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (1/1) ... [2022-11-16 10:58:51,706 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 10:58:51,722 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:58:51,740 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 10:58:51,763 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 10:58:51,802 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 10:58:51,802 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 10:58:51,803 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 10:58:51,803 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 10:58:51,803 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 10:58:51,803 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 10:58:51,803 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 10:58:51,805 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:58:51,806 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:58:51,806 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 10:58:51,806 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 10:58:51,806 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 10:58:51,806 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 10:58:51,807 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-16 10:58:51,807 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-16 10:58:51,808 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 10:58:51,808 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 10:58:51,808 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 10:58:51,808 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 10:58:51,808 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 10:58:51,910 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 10:58:51,911 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 10:58:52,348 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 10:58:52,363 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 10:58:52,363 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 10:58:52,366 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:58:52 BoogieIcfgContainer [2022-11-16 10:58:52,366 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 10:58:52,368 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 10:58:52,368 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 10:58:52,375 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 10:58:52,375 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 10:58:50" (1/3) ... [2022-11-16 10:58:52,377 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@47ed9a15 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 10:58:52, skipping insertion in model container [2022-11-16 10:58:52,377 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:58:51" (2/3) ... [2022-11-16 10:58:52,378 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@47ed9a15 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 10:58:52, skipping insertion in model container [2022-11-16 10:58:52,378 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:58:52" (3/3) ... [2022-11-16 10:58:52,379 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product53.cil.c [2022-11-16 10:58:52,399 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 10:58:52,400 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 10:58:52,471 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 10:58:52,479 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@406d95cc, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 10:58:52,479 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 10:58:52,488 INFO L276 IsEmpty]: Start isEmpty. Operand has 95 states, 71 states have (on average 1.3943661971830985) internal successors, (99), 81 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-16 10:58:52,500 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-16 10:58:52,501 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:52,501 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:52,502 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:52,510 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:52,510 INFO L85 PathProgramCache]: Analyzing trace with hash 1446250138, now seen corresponding path program 1 times [2022-11-16 10:58:52,519 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:52,520 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [516121432] [2022-11-16 10:58:52,520 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:52,521 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:52,716 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:52,853 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:52,854 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:52,854 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [516121432] [2022-11-16 10:58:52,855 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [516121432] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:52,855 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:52,855 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 10:58:52,857 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1700803265] [2022-11-16 10:58:52,857 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:52,862 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 10:58:52,862 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:52,899 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 10:58:52,900 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 10:58:52,905 INFO L87 Difference]: Start difference. First operand has 95 states, 71 states have (on average 1.3943661971830985) internal successors, (99), 81 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:52,972 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:52,972 INFO L93 Difference]: Finished difference Result 182 states and 249 transitions. [2022-11-16 10:58:52,974 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 10:58:52,976 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-16 10:58:52,977 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:52,988 INFO L225 Difference]: With dead ends: 182 [2022-11-16 10:58:52,989 INFO L226 Difference]: Without dead ends: 86 [2022-11-16 10:58:52,994 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 10:58:52,998 INFO L413 NwaCegarLoop]: 121 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 121 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:53,000 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:58:53,019 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 86 states. [2022-11-16 10:58:53,046 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 86 to 86. [2022-11-16 10:58:53,047 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 64 states have (on average 1.328125) internal successors, (85), 73 states have internal predecessors, (85), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-16 10:58:53,050 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 112 transitions. [2022-11-16 10:58:53,051 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 112 transitions. Word has length 19 [2022-11-16 10:58:53,052 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:53,052 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 112 transitions. [2022-11-16 10:58:53,052 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:53,053 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 112 transitions. [2022-11-16 10:58:53,054 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-16 10:58:53,054 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:53,055 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:53,055 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 10:58:53,055 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:53,056 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:53,056 INFO L85 PathProgramCache]: Analyzing trace with hash -1941246016, now seen corresponding path program 1 times [2022-11-16 10:58:53,056 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:53,057 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [522735922] [2022-11-16 10:58:53,057 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:53,057 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:53,085 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:53,187 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:53,187 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:53,187 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [522735922] [2022-11-16 10:58:53,188 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [522735922] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:53,188 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:53,188 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 10:58:53,188 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1710891392] [2022-11-16 10:58:53,188 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:53,191 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 10:58:53,191 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:53,192 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 10:58:53,192 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:58:53,192 INFO L87 Difference]: Start difference. First operand 86 states and 112 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:53,217 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:53,217 INFO L93 Difference]: Finished difference Result 138 states and 180 transitions. [2022-11-16 10:58:53,218 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 10:58:53,218 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-16 10:58:53,218 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:53,219 INFO L225 Difference]: With dead ends: 138 [2022-11-16 10:58:53,219 INFO L226 Difference]: Without dead ends: 77 [2022-11-16 10:58:53,220 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:58:53,221 INFO L413 NwaCegarLoop]: 99 mSDtfsCounter, 12 mSDsluCounter, 83 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 182 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:53,222 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [15 Valid, 182 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:58:53,223 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 77 states. [2022-11-16 10:58:53,232 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 77 to 77. [2022-11-16 10:58:53,233 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 77 states, 58 states have (on average 1.3448275862068966) internal successors, (78), 67 states have internal predecessors, (78), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 10:58:53,234 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 77 states to 77 states and 100 transitions. [2022-11-16 10:58:53,234 INFO L78 Accepts]: Start accepts. Automaton has 77 states and 100 transitions. Word has length 20 [2022-11-16 10:58:53,234 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:53,235 INFO L495 AbstractCegarLoop]: Abstraction has 77 states and 100 transitions. [2022-11-16 10:58:53,235 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:53,235 INFO L276 IsEmpty]: Start isEmpty. Operand 77 states and 100 transitions. [2022-11-16 10:58:53,236 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-16 10:58:53,236 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:53,237 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:53,237 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 10:58:53,237 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:53,238 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:53,238 INFO L85 PathProgramCache]: Analyzing trace with hash 626660710, now seen corresponding path program 1 times [2022-11-16 10:58:53,238 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:53,238 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1537030649] [2022-11-16 10:58:53,239 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:53,239 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:53,261 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:53,390 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:53,391 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:53,391 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1537030649] [2022-11-16 10:58:53,391 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1537030649] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:53,391 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:53,392 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 10:58:53,392 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1629390966] [2022-11-16 10:58:53,392 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:53,393 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:58:53,393 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:53,393 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:58:53,393 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:58:53,394 INFO L87 Difference]: Start difference. First operand 77 states and 100 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:53,508 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:53,508 INFO L93 Difference]: Finished difference Result 147 states and 194 transitions. [2022-11-16 10:58:53,509 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 10:58:53,509 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-11-16 10:58:53,510 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:53,511 INFO L225 Difference]: With dead ends: 147 [2022-11-16 10:58:53,511 INFO L226 Difference]: Without dead ends: 77 [2022-11-16 10:58:53,512 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-16 10:58:53,513 INFO L413 NwaCegarLoop]: 93 mSDtfsCounter, 126 mSDsluCounter, 116 mSDsCounter, 0 mSdLazyCounter, 49 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 126 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 59 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 49 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:53,514 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [126 Valid, 209 Invalid, 59 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 49 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 10:58:53,522 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 77 states. [2022-11-16 10:58:53,532 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 77 to 77. [2022-11-16 10:58:53,532 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 77 states, 58 states have (on average 1.3275862068965518) internal successors, (77), 67 states have internal predecessors, (77), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 10:58:53,533 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 77 states to 77 states and 99 transitions. [2022-11-16 10:58:53,534 INFO L78 Accepts]: Start accepts. Automaton has 77 states and 99 transitions. Word has length 24 [2022-11-16 10:58:53,534 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:53,534 INFO L495 AbstractCegarLoop]: Abstraction has 77 states and 99 transitions. [2022-11-16 10:58:53,535 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:58:53,535 INFO L276 IsEmpty]: Start isEmpty. Operand 77 states and 99 transitions. [2022-11-16 10:58:53,536 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-16 10:58:53,536 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:53,536 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:53,537 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 10:58:53,537 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:53,537 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:53,538 INFO L85 PathProgramCache]: Analyzing trace with hash 222843713, now seen corresponding path program 1 times [2022-11-16 10:58:53,538 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:53,538 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [738168364] [2022-11-16 10:58:53,538 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:53,539 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:53,558 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:53,626 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2022-11-16 10:58:53,628 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:53,630 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:53,631 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:53,631 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [738168364] [2022-11-16 10:58:53,631 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [738168364] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:53,631 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:53,632 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-16 10:58:53,632 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2043441494] [2022-11-16 10:58:53,632 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:53,632 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-16 10:58:53,633 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:53,633 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-16 10:58:53,633 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-16 10:58:53,634 INFO L87 Difference]: Start difference. First operand 77 states and 99 transitions. Second operand has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 10:58:53,846 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:53,846 INFO L93 Difference]: Finished difference Result 217 states and 282 transitions. [2022-11-16 10:58:53,847 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 10:58:53,847 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 33 [2022-11-16 10:58:53,847 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:53,854 INFO L225 Difference]: With dead ends: 217 [2022-11-16 10:58:53,855 INFO L226 Difference]: Without dead ends: 147 [2022-11-16 10:58:53,859 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-16 10:58:53,865 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 137 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 72 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 140 SdHoareTripleChecker+Valid, 201 SdHoareTripleChecker+Invalid, 108 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 72 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:53,869 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [140 Valid, 201 Invalid, 108 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 72 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:58:53,872 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 147 states. [2022-11-16 10:58:53,893 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 147 to 141. [2022-11-16 10:58:53,893 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 141 states, 108 states have (on average 1.287037037037037) internal successors, (139), 116 states have internal predecessors, (139), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 10:58:53,895 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 141 states to 141 states and 178 transitions. [2022-11-16 10:58:53,895 INFO L78 Accepts]: Start accepts. Automaton has 141 states and 178 transitions. Word has length 33 [2022-11-16 10:58:53,895 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:53,896 INFO L495 AbstractCegarLoop]: Abstraction has 141 states and 178 transitions. [2022-11-16 10:58:53,896 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 7.5) internal successors, (30), 3 states have internal predecessors, (30), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 10:58:53,896 INFO L276 IsEmpty]: Start isEmpty. Operand 141 states and 178 transitions. [2022-11-16 10:58:53,897 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-16 10:58:53,897 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:53,897 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:53,898 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 10:58:53,898 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:53,898 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:53,898 INFO L85 PathProgramCache]: Analyzing trace with hash 569930082, now seen corresponding path program 1 times [2022-11-16 10:58:53,899 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:53,899 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [300598880] [2022-11-16 10:58:53,899 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:53,899 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:53,917 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,007 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:58:54,014 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,030 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:54,040 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,073 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:54,073 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:54,073 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [300598880] [2022-11-16 10:58:54,073 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [300598880] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:54,074 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:54,074 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 10:58:54,074 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1006429085] [2022-11-16 10:58:54,074 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:54,075 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:58:54,075 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:54,075 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:58:54,076 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:58:54,076 INFO L87 Difference]: Start difference. First operand 141 states and 178 transitions. Second operand has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:58:54,258 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:54,258 INFO L93 Difference]: Finished difference Result 283 states and 365 transitions. [2022-11-16 10:58:54,259 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 10:58:54,260 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-11-16 10:58:54,260 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:54,265 INFO L225 Difference]: With dead ends: 283 [2022-11-16 10:58:54,268 INFO L226 Difference]: Without dead ends: 149 [2022-11-16 10:58:54,269 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-16 10:58:54,270 INFO L413 NwaCegarLoop]: 90 mSDtfsCounter, 68 mSDsluCounter, 297 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 387 SdHoareTripleChecker+Invalid, 144 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:54,274 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 387 Invalid, 144 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 10:58:54,275 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 149 states. [2022-11-16 10:58:54,303 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 149 to 144. [2022-11-16 10:58:54,305 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 144 states, 111 states have (on average 1.2792792792792793) internal successors, (142), 119 states have internal predecessors, (142), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 10:58:54,308 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 144 states to 144 states and 181 transitions. [2022-11-16 10:58:54,308 INFO L78 Accepts]: Start accepts. Automaton has 144 states and 181 transitions. Word has length 43 [2022-11-16 10:58:54,309 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:54,309 INFO L495 AbstractCegarLoop]: Abstraction has 144 states and 181 transitions. [2022-11-16 10:58:54,310 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:58:54,310 INFO L276 IsEmpty]: Start isEmpty. Operand 144 states and 181 transitions. [2022-11-16 10:58:54,312 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-16 10:58:54,312 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:54,312 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:54,313 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 10:58:54,313 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:54,313 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:54,313 INFO L85 PathProgramCache]: Analyzing trace with hash -451138272, now seen corresponding path program 1 times [2022-11-16 10:58:54,314 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:54,314 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2087955388] [2022-11-16 10:58:54,314 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:54,314 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:54,337 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,436 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:58:54,441 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,459 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:54,467 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,506 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:54,507 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:54,507 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2087955388] [2022-11-16 10:58:54,507 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2087955388] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:54,507 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:54,508 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 10:58:54,508 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [512654511] [2022-11-16 10:58:54,508 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:54,508 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 10:58:54,509 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:54,509 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 10:58:54,510 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:58:54,511 INFO L87 Difference]: Start difference. First operand 144 states and 181 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:58:54,710 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:54,710 INFO L93 Difference]: Finished difference Result 294 states and 384 transitions. [2022-11-16 10:58:54,711 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-16 10:58:54,711 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-11-16 10:58:54,712 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:54,713 INFO L225 Difference]: With dead ends: 294 [2022-11-16 10:58:54,713 INFO L226 Difference]: Without dead ends: 157 [2022-11-16 10:58:54,714 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=30, Invalid=80, Unknown=0, NotChecked=0, Total=110 [2022-11-16 10:58:54,715 INFO L413 NwaCegarLoop]: 89 mSDtfsCounter, 109 mSDsluCounter, 344 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 111 SdHoareTripleChecker+Valid, 433 SdHoareTripleChecker+Invalid, 187 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:54,715 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [111 Valid, 433 Invalid, 187 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 10:58:54,716 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 157 states. [2022-11-16 10:58:54,751 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 157 to 146. [2022-11-16 10:58:54,752 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 146 states, 113 states have (on average 1.2743362831858407) internal successors, (144), 121 states have internal predecessors, (144), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 10:58:54,753 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 146 states to 146 states and 183 transitions. [2022-11-16 10:58:54,754 INFO L78 Accepts]: Start accepts. Automaton has 146 states and 183 transitions. Word has length 43 [2022-11-16 10:58:54,755 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:54,755 INFO L495 AbstractCegarLoop]: Abstraction has 146 states and 183 transitions. [2022-11-16 10:58:54,756 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:58:54,756 INFO L276 IsEmpty]: Start isEmpty. Operand 146 states and 183 transitions. [2022-11-16 10:58:54,763 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-11-16 10:58:54,764 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:54,765 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:54,765 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 10:58:54,766 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:54,766 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:54,766 INFO L85 PathProgramCache]: Analyzing trace with hash 1849684318, now seen corresponding path program 1 times [2022-11-16 10:58:54,766 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:54,767 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [46856318] [2022-11-16 10:58:54,768 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:54,768 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:54,787 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,888 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:58:54,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,913 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:54,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:54,938 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:54,938 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:54,939 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [46856318] [2022-11-16 10:58:54,939 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [46856318] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:54,939 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:54,939 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 10:58:54,940 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [251842447] [2022-11-16 10:58:54,940 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:54,940 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 10:58:54,940 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:54,941 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 10:58:54,941 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 10:58:54,941 INFO L87 Difference]: Start difference. First operand 146 states and 183 transitions. Second operand has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:58:55,224 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:55,224 INFO L93 Difference]: Finished difference Result 407 states and 536 transitions. [2022-11-16 10:58:55,225 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 10:58:55,225 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 43 [2022-11-16 10:58:55,226 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:55,228 INFO L225 Difference]: With dead ends: 407 [2022-11-16 10:58:55,228 INFO L226 Difference]: Without dead ends: 268 [2022-11-16 10:58:55,229 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:58:55,230 INFO L413 NwaCegarLoop]: 132 mSDtfsCounter, 201 mSDsluCounter, 177 mSDsCounter, 0 mSdLazyCounter, 165 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 205 SdHoareTripleChecker+Valid, 309 SdHoareTripleChecker+Invalid, 219 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 165 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:55,230 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [205 Valid, 309 Invalid, 219 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 165 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:58:55,232 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 268 states. [2022-11-16 10:58:55,283 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 268 to 260. [2022-11-16 10:58:55,284 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 260 states, 199 states have (on average 1.256281407035176) internal successors, (250), 211 states have internal predecessors, (250), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-16 10:58:55,286 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 260 states to 260 states and 334 transitions. [2022-11-16 10:58:55,287 INFO L78 Accepts]: Start accepts. Automaton has 260 states and 334 transitions. Word has length 43 [2022-11-16 10:58:55,287 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:55,287 INFO L495 AbstractCegarLoop]: Abstraction has 260 states and 334 transitions. [2022-11-16 10:58:55,287 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 4 states have internal predecessors, (38), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:58:55,288 INFO L276 IsEmpty]: Start isEmpty. Operand 260 states and 334 transitions. [2022-11-16 10:58:55,290 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-11-16 10:58:55,291 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:55,291 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:55,291 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 10:58:55,292 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:55,292 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:55,292 INFO L85 PathProgramCache]: Analyzing trace with hash -784742271, now seen corresponding path program 1 times [2022-11-16 10:58:55,292 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:55,292 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [779078421] [2022-11-16 10:58:55,295 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:55,295 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:55,315 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,466 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:58:55,469 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,475 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:55,488 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,491 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:58:55,491 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,493 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:55,493 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:55,493 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [779078421] [2022-11-16 10:58:55,493 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [779078421] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:55,493 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:55,493 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 10:58:55,493 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1783849974] [2022-11-16 10:58:55,494 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:55,494 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:58:55,494 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:55,494 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:58:55,495 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:58:55,495 INFO L87 Difference]: Start difference. First operand 260 states and 334 transitions. Second operand has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 10:58:55,717 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:55,717 INFO L93 Difference]: Finished difference Result 513 states and 660 transitions. [2022-11-16 10:58:55,718 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 10:58:55,718 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 45 [2022-11-16 10:58:55,718 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:55,723 INFO L225 Difference]: With dead ends: 513 [2022-11-16 10:58:55,723 INFO L226 Difference]: Without dead ends: 260 [2022-11-16 10:58:55,724 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-16 10:58:55,725 INFO L413 NwaCegarLoop]: 84 mSDtfsCounter, 114 mSDsluCounter, 277 mSDsCounter, 0 mSdLazyCounter, 146 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 117 SdHoareTripleChecker+Valid, 361 SdHoareTripleChecker+Invalid, 173 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 146 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:55,726 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [117 Valid, 361 Invalid, 173 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 146 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 10:58:55,729 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 260 states. [2022-11-16 10:58:55,758 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 260 to 258. [2022-11-16 10:58:55,758 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 258 states, 197 states have (on average 1.248730964467005) internal successors, (246), 209 states have internal predecessors, (246), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-16 10:58:55,761 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 258 states to 258 states and 330 transitions. [2022-11-16 10:58:55,762 INFO L78 Accepts]: Start accepts. Automaton has 258 states and 330 transitions. Word has length 45 [2022-11-16 10:58:55,764 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:55,764 INFO L495 AbstractCegarLoop]: Abstraction has 258 states and 330 transitions. [2022-11-16 10:58:55,764 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 5 states have internal predecessors, (38), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 10:58:55,764 INFO L276 IsEmpty]: Start isEmpty. Operand 258 states and 330 transitions. [2022-11-16 10:58:55,765 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 10:58:55,765 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:55,765 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:55,765 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 10:58:55,766 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:55,766 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:55,767 INFO L85 PathProgramCache]: Analyzing trace with hash 1315447288, now seen corresponding path program 1 times [2022-11-16 10:58:55,767 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:55,767 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1056009032] [2022-11-16 10:58:55,767 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:55,767 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:55,785 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:58:55,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,904 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 10:58:55,908 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,918 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:55,920 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:55,930 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:55,930 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:55,930 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1056009032] [2022-11-16 10:58:55,930 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1056009032] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:58:55,931 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:58:55,931 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 10:58:55,931 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [35340594] [2022-11-16 10:58:55,931 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:58:55,936 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 10:58:55,936 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:55,937 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 10:58:55,937 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:58:55,937 INFO L87 Difference]: Start difference. First operand 258 states and 330 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 10:58:56,501 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:58:56,501 INFO L93 Difference]: Finished difference Result 538 states and 711 transitions. [2022-11-16 10:58:56,502 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-16 10:58:56,502 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2022-11-16 10:58:56,503 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:58:56,506 INFO L225 Difference]: With dead ends: 538 [2022-11-16 10:58:56,506 INFO L226 Difference]: Without dead ends: 332 [2022-11-16 10:58:56,508 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 58 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-11-16 10:58:56,510 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 204 mSDsluCounter, 338 mSDsCounter, 0 mSdLazyCounter, 432 mSolverCounterSat, 67 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 205 SdHoareTripleChecker+Valid, 434 SdHoareTripleChecker+Invalid, 499 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 67 IncrementalHoareTripleChecker+Valid, 432 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-16 10:58:56,511 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [205 Valid, 434 Invalid, 499 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [67 Valid, 432 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-16 10:58:56,512 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 332 states. [2022-11-16 10:58:56,552 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 332 to 297. [2022-11-16 10:58:56,553 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 297 states, 228 states have (on average 1.2236842105263157) internal successors, (279), 244 states have internal predecessors, (279), 32 states have call successors, (32), 28 states have call predecessors, (32), 36 states have return successors, (69), 34 states have call predecessors, (69), 32 states have call successors, (69) [2022-11-16 10:58:56,555 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 297 states to 297 states and 380 transitions. [2022-11-16 10:58:56,555 INFO L78 Accepts]: Start accepts. Automaton has 297 states and 380 transitions. Word has length 47 [2022-11-16 10:58:56,555 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:58:56,556 INFO L495 AbstractCegarLoop]: Abstraction has 297 states and 380 transitions. [2022-11-16 10:58:56,556 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 10:58:56,556 INFO L276 IsEmpty]: Start isEmpty. Operand 297 states and 380 transitions. [2022-11-16 10:58:56,557 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 76 [2022-11-16 10:58:56,557 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:58:56,558 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:58:56,558 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-16 10:58:56,558 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:58:56,558 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:58:56,559 INFO L85 PathProgramCache]: Analyzing trace with hash -949050969, now seen corresponding path program 1 times [2022-11-16 10:58:56,559 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:58:56,559 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1875252791] [2022-11-16 10:58:56,559 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:56,559 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:58:56,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,685 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:58:56,686 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,700 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:58:56,704 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,719 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:58:56,721 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:58:56,726 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,729 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-11-16 10:58:56,730 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,732 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 6 proven. 1 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-16 10:58:56,732 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:58:56,732 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1875252791] [2022-11-16 10:58:56,733 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1875252791] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 10:58:56,733 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2128877696] [2022-11-16 10:58:56,733 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:58:56,733 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:58:56,733 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:58:56,739 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 10:58:56,773 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 10:58:56,879 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:58:56,882 INFO L263 TraceCheckSpWp]: Trace formula consists of 418 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-16 10:58:56,889 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 10:58:57,101 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:57,104 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 10:58:57,333 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:58:57,333 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2128877696] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 10:58:57,333 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 10:58:57,333 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 13 [2022-11-16 10:58:57,334 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1700500920] [2022-11-16 10:58:57,334 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 10:58:57,334 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-16 10:58:57,335 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:58:57,335 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-16 10:58:57,335 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=130, Unknown=0, NotChecked=0, Total=156 [2022-11-16 10:58:57,336 INFO L87 Difference]: Start difference. First operand 297 states and 380 transitions. Second operand has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-16 10:59:00,203 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:59:00,203 INFO L93 Difference]: Finished difference Result 1351 states and 1825 transitions. [2022-11-16 10:59:00,204 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 101 states. [2022-11-16 10:59:00,204 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) Word has length 75 [2022-11-16 10:59:00,204 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:59:00,210 INFO L225 Difference]: With dead ends: 1351 [2022-11-16 10:59:00,210 INFO L226 Difference]: Without dead ends: 1061 [2022-11-16 10:59:00,216 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 289 GetRequests, 180 SyntacticMatches, 6 SemanticMatches, 103 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4125 ImplicationChecksByTransitivity, 1.5s TimeCoverageRelationStatistics Valid=1749, Invalid=9171, Unknown=0, NotChecked=0, Total=10920 [2022-11-16 10:59:00,216 INFO L413 NwaCegarLoop]: 137 mSDtfsCounter, 883 mSDsluCounter, 974 mSDsCounter, 0 mSdLazyCounter, 1712 mSolverCounterSat, 391 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 889 SdHoareTripleChecker+Valid, 1111 SdHoareTripleChecker+Invalid, 2103 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 391 IncrementalHoareTripleChecker+Valid, 1712 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.3s IncrementalHoareTripleChecker+Time [2022-11-16 10:59:00,217 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [889 Valid, 1111 Invalid, 2103 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [391 Valid, 1712 Invalid, 0 Unknown, 0 Unchecked, 1.3s Time] [2022-11-16 10:59:00,218 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1061 states. [2022-11-16 10:59:00,345 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1061 to 836. [2022-11-16 10:59:00,347 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 836 states, 638 states have (on average 1.206896551724138) internal successors, (770), 680 states have internal predecessors, (770), 91 states have call successors, (91), 82 states have call predecessors, (91), 106 states have return successors, (222), 96 states have call predecessors, (222), 91 states have call successors, (222) [2022-11-16 10:59:00,353 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 836 states to 836 states and 1083 transitions. [2022-11-16 10:59:00,355 INFO L78 Accepts]: Start accepts. Automaton has 836 states and 1083 transitions. Word has length 75 [2022-11-16 10:59:00,355 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:59:00,356 INFO L495 AbstractCegarLoop]: Abstraction has 836 states and 1083 transitions. [2022-11-16 10:59:00,356 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 13 states have (on average 8.76923076923077) internal successors, (114), 10 states have internal predecessors, (114), 5 states have call successors, (13), 7 states have call predecessors, (13), 3 states have return successors, (11), 5 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-16 10:59:00,356 INFO L276 IsEmpty]: Start isEmpty. Operand 836 states and 1083 transitions. [2022-11-16 10:59:00,360 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 122 [2022-11-16 10:59:00,360 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:59:00,360 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:59:00,371 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-16 10:59:00,566 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:59:00,566 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:59:00,567 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:59:00,567 INFO L85 PathProgramCache]: Analyzing trace with hash -1084284902, now seen corresponding path program 1 times [2022-11-16 10:59:00,567 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:59:00,567 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [317983140] [2022-11-16 10:59:00,568 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:59:00,568 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:59:00,594 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,708 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:59:00,709 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,718 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:59:00,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,738 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:59:00,740 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,743 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:59:00,744 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,746 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-16 10:59:00,750 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,758 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:59:00,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,762 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 10:59:00,763 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,765 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:59:00,766 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,773 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 95 [2022-11-16 10:59:00,774 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,776 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 110 [2022-11-16 10:59:00,776 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,780 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 54 trivial. 0 not checked. [2022-11-16 10:59:00,780 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:59:00,781 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [317983140] [2022-11-16 10:59:00,781 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [317983140] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 10:59:00,781 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1100933376] [2022-11-16 10:59:00,781 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:59:00,781 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:59:00,781 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:59:00,782 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 10:59:00,807 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 10:59:00,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:00,911 INFO L263 TraceCheckSpWp]: Trace formula consists of 536 conjuncts, 11 conjunts are in the unsatisfiable core [2022-11-16 10:59:00,915 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 10:59:01,212 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 51 proven. 11 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 10:59:01,214 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 10:59:01,608 INFO L134 CoverageAnalysis]: Checked inductivity of 64 backedges. 49 proven. 11 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-16 10:59:01,609 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1100933376] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 10:59:01,609 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 10:59:01,609 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 9, 9] total 21 [2022-11-16 10:59:01,609 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1023436943] [2022-11-16 10:59:01,609 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 10:59:01,610 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 21 states [2022-11-16 10:59:01,610 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:59:01,611 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 21 interpolants. [2022-11-16 10:59:01,611 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=69, Invalid=351, Unknown=0, NotChecked=0, Total=420 [2022-11-16 10:59:01,611 INFO L87 Difference]: Start difference. First operand 836 states and 1083 transitions. Second operand has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) [2022-11-16 10:59:05,215 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:59:05,216 INFO L93 Difference]: Finished difference Result 2384 states and 3309 transitions. [2022-11-16 10:59:05,216 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 70 states. [2022-11-16 10:59:05,217 INFO L78 Accepts]: Start accepts. Automaton has has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) Word has length 121 [2022-11-16 10:59:05,217 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:59:05,226 INFO L225 Difference]: With dead ends: 2384 [2022-11-16 10:59:05,226 INFO L226 Difference]: Without dead ends: 1647 [2022-11-16 10:59:05,234 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 367 GetRequests, 284 SyntacticMatches, 1 SemanticMatches, 82 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1861 ImplicationChecksByTransitivity, 1.6s TimeCoverageRelationStatistics Valid=1289, Invalid=5683, Unknown=0, NotChecked=0, Total=6972 [2022-11-16 10:59:05,234 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 1189 mSDsluCounter, 548 mSDsCounter, 0 mSdLazyCounter, 2633 mSolverCounterSat, 623 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1195 SdHoareTripleChecker+Valid, 635 SdHoareTripleChecker+Invalid, 3256 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 623 IncrementalHoareTripleChecker+Valid, 2633 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:59:05,235 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1195 Valid, 635 Invalid, 3256 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [623 Valid, 2633 Invalid, 0 Unknown, 0 Unchecked, 2.0s Time] [2022-11-16 10:59:05,237 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1647 states. [2022-11-16 10:59:05,418 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1647 to 1331. [2022-11-16 10:59:05,421 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1331 states, 1004 states have (on average 1.198207171314741) internal successors, (1203), 1061 states have internal predecessors, (1203), 152 states have call successors, (152), 142 states have call predecessors, (152), 174 states have return successors, (343), 158 states have call predecessors, (343), 152 states have call successors, (343) [2022-11-16 10:59:05,428 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1331 states to 1331 states and 1698 transitions. [2022-11-16 10:59:05,429 INFO L78 Accepts]: Start accepts. Automaton has 1331 states and 1698 transitions. Word has length 121 [2022-11-16 10:59:05,430 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:59:05,430 INFO L495 AbstractCegarLoop]: Abstraction has 1331 states and 1698 transitions. [2022-11-16 10:59:05,431 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 21 states, 21 states have (on average 7.9523809523809526) internal successors, (167), 17 states have internal predecessors, (167), 6 states have call successors, (25), 9 states have call predecessors, (25), 7 states have return successors, (23), 7 states have call predecessors, (23), 6 states have call successors, (23) [2022-11-16 10:59:05,431 INFO L276 IsEmpty]: Start isEmpty. Operand 1331 states and 1698 transitions. [2022-11-16 10:59:05,442 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2022-11-16 10:59:05,442 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:59:05,443 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:59:05,456 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 10:59:05,648 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:59:05,649 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:59:05,649 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:59:05,649 INFO L85 PathProgramCache]: Analyzing trace with hash -1154537432, now seen corresponding path program 1 times [2022-11-16 10:59:05,649 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:59:05,649 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [885748186] [2022-11-16 10:59:05,650 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:59:05,650 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:59:05,668 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,773 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:59:05,775 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,782 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 10:59:05,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,792 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:59:05,793 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,796 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:59:05,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-16 10:59:05,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,853 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:59:05,858 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,908 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 10:59:05,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,910 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:59:05,911 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,912 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-11-16 10:59:05,914 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,917 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 10:59:05,918 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,919 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:59:05,920 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:05,921 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 41 trivial. 0 not checked. [2022-11-16 10:59:05,921 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:59:05,922 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [885748186] [2022-11-16 10:59:05,922 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [885748186] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 10:59:05,922 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [314655071] [2022-11-16 10:59:05,922 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:59:05,922 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:59:05,923 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:59:05,924 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 10:59:05,929 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 10:59:06,077 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:59:06,079 INFO L263 TraceCheckSpWp]: Trace formula consists of 563 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-16 10:59:06,082 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 10:59:06,123 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 62 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-11-16 10:59:06,123 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 10:59:06,124 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [314655071] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:59:06,124 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 10:59:06,124 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [10] total 12 [2022-11-16 10:59:06,124 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [984631795] [2022-11-16 10:59:06,124 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:59:06,125 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 10:59:06,125 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:59:06,125 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 10:59:06,126 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=25, Invalid=107, Unknown=0, NotChecked=0, Total=132 [2022-11-16 10:59:06,126 INFO L87 Difference]: Start difference. First operand 1331 states and 1698 transitions. Second operand has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 10:59:06,210 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:59:06,210 INFO L93 Difference]: Finished difference Result 1762 states and 2225 transitions. [2022-11-16 10:59:06,210 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 10:59:06,211 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 131 [2022-11-16 10:59:06,211 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:59:06,211 INFO L225 Difference]: With dead ends: 1762 [2022-11-16 10:59:06,212 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 10:59:06,215 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 170 GetRequests, 158 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=38, Invalid=144, Unknown=0, NotChecked=0, Total=182 [2022-11-16 10:59:06,216 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 9 mSDsluCounter, 274 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 371 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:59:06,216 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 371 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:59:06,217 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 10:59:06,217 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 10:59:06,217 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:59:06,217 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 10:59:06,218 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 131 [2022-11-16 10:59:06,218 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:59:06,218 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 10:59:06,218 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 10:59:06,218 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 10:59:06,219 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 10:59:06,221 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 10:59:06,232 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 10:59:06,427 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-16 10:59:06,429 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 10:59:11,064 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 615 622) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:59:11,064 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 615 622) no Hoare annotation was computed. [2022-11-16 10:59:11,064 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 615 622) no Hoare annotation was computed. [2022-11-16 10:59:11,064 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 522 528) no Hoare annotation was computed. [2022-11-16 10:59:11,064 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 522 528) the Hoare annotation is: true [2022-11-16 10:59:11,065 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 792 803) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0))) (and (or (not (= ~waterLevel~0 1)) (not (= ~pumpRunning~0 0)) .cse0 .cse1) (or .cse0 .cse1 (< ~waterLevel~0 2)))) [2022-11-16 10:59:11,065 INFO L899 garLoopResultBuilder]: For program point L796-1(lines 792 803) no Hoare annotation was computed. [2022-11-16 10:59:11,065 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 792 803) no Hoare annotation was computed. [2022-11-16 10:59:11,065 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 896 925) no Hoare annotation was computed. [2022-11-16 10:59:11,065 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 896 925) the Hoare annotation is: true [2022-11-16 10:59:11,065 INFO L902 garLoopResultBuilder]: At program point L921(lines 896 925) the Hoare annotation is: true [2022-11-16 10:59:11,066 INFO L899 garLoopResultBuilder]: For program point L917(line 917) no Hoare annotation was computed. [2022-11-16 10:59:11,066 INFO L899 garLoopResultBuilder]: For program point L910(lines 910 914) no Hoare annotation was computed. [2022-11-16 10:59:11,066 INFO L902 garLoopResultBuilder]: At program point L910-1(lines 910 914) the Hoare annotation is: true [2022-11-16 10:59:11,066 INFO L899 garLoopResultBuilder]: For program point L907(line 907) no Hoare annotation was computed. [2022-11-16 10:59:11,066 INFO L902 garLoopResultBuilder]: At program point L906-2(lines 906 920) the Hoare annotation is: true [2022-11-16 10:59:11,066 INFO L902 garLoopResultBuilder]: At program point L902(line 902) the Hoare annotation is: true [2022-11-16 10:59:11,067 INFO L899 garLoopResultBuilder]: For program point L902-1(line 902) no Hoare annotation was computed. [2022-11-16 10:59:11,067 INFO L895 garLoopResultBuilder]: At program point L601(line 601) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-16 10:59:11,067 INFO L895 garLoopResultBuilder]: At program point L601-1(lines 582 606) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (<= 2 ~waterLevel~0)) (.cse4 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) (or .cse0 .cse2 (not (= |old(~waterLevel~0)| 1)) .cse1) (let ((.cse3 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse2 .cse3) .cse1 .cse4 (and .cse5 .cse3))) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse1 .cse5 .cse4 (not (= ~methaneLevelCritical~0 0))))) [2022-11-16 10:59:11,067 INFO L895 garLoopResultBuilder]: At program point L630(lines 623 633) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (and (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0))) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 10:59:11,068 INFO L899 garLoopResultBuilder]: For program point L502-1(lines 501 520) no Hoare annotation was computed. [2022-11-16 10:59:11,068 INFO L895 garLoopResultBuilder]: At program point L841(lines 836 844) the Hoare annotation is: (let ((.cse4 (<= 2 ~waterLevel~0)) (.cse3 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (< |old(~waterLevel~0)| 2)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse6 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse3)) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse1 (and .cse4 .cse3) .cse2 (not (= ~methaneLevelCritical~0 0))) (let ((.cse5 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse4 .cse5 .cse3) .cse1 .cse2 (and .cse6 .cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse6 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-16 10:59:11,068 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 498 521) no Hoare annotation was computed. [2022-11-16 10:59:11,068 INFO L895 garLoopResultBuilder]: At program point L639(lines 634 642) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-16 10:59:11,069 INFO L899 garLoopResultBuilder]: For program point L590(lines 590 598) no Hoare annotation was computed. [2022-11-16 10:59:11,069 INFO L899 garLoopResultBuilder]: For program point L586(lines 586 603) no Hoare annotation was computed. [2022-11-16 10:59:11,069 INFO L895 garLoopResultBuilder]: At program point L809(lines 804 812) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 10:59:11,069 INFO L899 garLoopResultBuilder]: For program point L772(lines 772 776) no Hoare annotation was computed. [2022-11-16 10:59:11,069 INFO L895 garLoopResultBuilder]: At program point L772-2(lines 768 779) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 10:59:11,070 INFO L899 garLoopResultBuilder]: For program point L760(line 760) no Hoare annotation was computed. [2022-11-16 10:59:11,070 INFO L899 garLoopResultBuilder]: For program point L509-1(lines 509 515) no Hoare annotation was computed. [2022-11-16 10:59:11,070 INFO L895 garLoopResultBuilder]: At program point L761(lines 756 763) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-16 10:59:11,070 INFO L895 garLoopResultBuilder]: At program point L596(line 596) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (and (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_processEnvironment_~tmp~6#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse1))) [2022-11-16 10:59:11,070 INFO L899 garLoopResultBuilder]: For program point L881(lines 881 887) no Hoare annotation was computed. [2022-11-16 10:59:11,071 INFO L895 garLoopResultBuilder]: At program point L592(line 592) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (< |old(~waterLevel~0)| 2))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2022-11-16 10:59:11,071 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 498 521) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-16 10:59:11,071 INFO L899 garLoopResultBuilder]: For program point L877(lines 877 890) no Hoare annotation was computed. [2022-11-16 10:59:11,071 INFO L895 garLoopResultBuilder]: At program point L877-1(lines 869 893) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= ~pumpRunning~0 0)) (.cse3 (not (= 1 ~systemActive~0))) (.cse4 (< |old(~waterLevel~0)| 2)) (.cse1 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|))) (and (or .cse0 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1 .cse2) .cse3 .cse4) (let ((.cse5 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and (<= 2 ~waterLevel~0) .cse5 .cse1 .cse2) .cse3 (and .cse6 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|) .cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)) .cse4)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1| 1) .cse6 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or (and (= |timeShift_processEnvironment_~tmp~6#1| 0) (= |timeShift_isMethaneAlarm_#res#1| 0) (= |timeShift_isMethaneLevelCritical_#res#1| 0)) .cse3 .cse4 (and (not (< ~waterLevel~0 2)) .cse1 .cse2) (not (= ~methaneLevelCritical~0 0))))) [2022-11-16 10:59:11,072 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 498 521) no Hoare annotation was computed. [2022-11-16 10:59:11,072 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 760) no Hoare annotation was computed. [2022-11-16 10:59:11,072 INFO L895 garLoopResultBuilder]: At program point L473(lines 430 475) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-16 10:59:11,072 INFO L899 garLoopResultBuilder]: For program point L440(lines 440 446) no Hoare annotation was computed. [2022-11-16 10:59:11,072 INFO L899 garLoopResultBuilder]: For program point L440-1(lines 440 446) no Hoare annotation was computed. [2022-11-16 10:59:11,072 INFO L899 garLoopResultBuilder]: For program point L977(lines 977 984) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point L977-2(lines 977 984) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L902 garLoopResultBuilder]: At program point L986(lines 967 989) the Hoare annotation is: true [2022-11-16 10:59:11,073 INFO L899 garLoopResultBuilder]: For program point L466(lines 466 470) no Hoare annotation was computed. [2022-11-16 10:59:11,073 INFO L895 garLoopResultBuilder]: At program point L466-2(lines 460 471) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-16 10:59:11,074 INFO L895 garLoopResultBuilder]: At program point L751(lines 746 754) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:59:11,074 INFO L895 garLoopResultBuilder]: At program point L743(lines 739 745) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:59:11,074 INFO L899 garLoopResultBuilder]: For program point L450(lines 450 456) no Hoare annotation was computed. [2022-11-16 10:59:11,074 INFO L899 garLoopResultBuilder]: For program point L450-1(lines 450 456) no Hoare annotation was computed. [2022-11-16 10:59:11,074 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 10:59:11,074 INFO L902 garLoopResultBuilder]: At program point L479(lines 420 483) the Hoare annotation is: true [2022-11-16 10:59:11,075 INFO L895 garLoopResultBuilder]: At program point L954(lines 950 956) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~10#1| 1)) [2022-11-16 10:59:11,075 INFO L895 garLoopResultBuilder]: At program point L442(line 442) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-16 10:59:11,075 INFO L895 garLoopResultBuilder]: At program point L736(lines 732 738) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:59:11,075 INFO L895 garLoopResultBuilder]: At program point L476(lines 429 477) the Hoare annotation is: false [2022-11-16 10:59:11,075 INFO L899 garLoopResultBuilder]: For program point L431(lines 430 475) no Hoare annotation was computed. [2022-11-16 10:59:11,075 INFO L899 garLoopResultBuilder]: For program point L460(lines 460 471) no Hoare annotation was computed. [2022-11-16 10:59:11,076 INFO L895 garLoopResultBuilder]: At program point L452(line 452) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0) .cse3))) [2022-11-16 10:59:11,076 INFO L902 garLoopResultBuilder]: At program point L964(lines 957 966) the Hoare annotation is: true [2022-11-16 10:59:11,076 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 530 554) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:59:11,076 INFO L895 garLoopResultBuilder]: At program point L694(lines 679 697) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~7#1| 0)) .cse0 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (and .cse0 (<= 2 ~waterLevel~0)))) [2022-11-16 10:59:11,076 INFO L899 garLoopResultBuilder]: For program point L849(lines 849 855) no Hoare annotation was computed. [2022-11-16 10:59:11,076 INFO L899 garLoopResultBuilder]: For program point L688(lines 688 692) no Hoare annotation was computed. [2022-11-16 10:59:11,077 INFO L899 garLoopResultBuilder]: For program point L688-2(lines 688 692) no Hoare annotation was computed. [2022-11-16 10:59:11,077 INFO L895 garLoopResultBuilder]: At program point L612(lines 607 614) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-11-16 10:59:11,077 INFO L895 garLoopResultBuilder]: At program point L544(line 544) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_~tmp~4#1| 0))) [2022-11-16 10:59:11,077 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 530 554) no Hoare annotation was computed. [2022-11-16 10:59:11,077 INFO L899 garLoopResultBuilder]: For program point L538(lines 538 546) no Hoare annotation was computed. [2022-11-16 10:59:11,077 INFO L899 garLoopResultBuilder]: For program point L534(lines 534 551) no Hoare annotation was computed. [2022-11-16 10:59:11,078 INFO L895 garLoopResultBuilder]: At program point L854(lines 845 858) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 .cse2 (and .cse1 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))))) [2022-11-16 10:59:11,078 INFO L895 garLoopResultBuilder]: At program point L549(line 549) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:59:11,078 INFO L899 garLoopResultBuilder]: For program point L549-1(lines 530 554) no Hoare annotation was computed. [2022-11-16 10:59:11,078 INFO L899 garLoopResultBuilder]: For program point L784-1(lines 780 791) no Hoare annotation was computed. [2022-11-16 10:59:11,078 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 780 791) no Hoare annotation was computed. [2022-11-16 10:59:11,078 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 780 791) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:59:11,079 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 556 580) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:59:11,079 INFO L895 garLoopResultBuilder]: At program point L570(line 570) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:59:11,079 INFO L895 garLoopResultBuilder]: At program point L566(line 566) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~5#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))))) [2022-11-16 10:59:11,079 INFO L899 garLoopResultBuilder]: For program point L564(lines 564 572) no Hoare annotation was computed. [2022-11-16 10:59:11,079 INFO L899 garLoopResultBuilder]: For program point L560(lines 560 577) no Hoare annotation was computed. [2022-11-16 10:59:11,080 INFO L895 garLoopResultBuilder]: At program point L713(lines 698 716) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~8#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 10:59:11,080 INFO L899 garLoopResultBuilder]: For program point L707(lines 707 711) no Hoare annotation was computed. [2022-11-16 10:59:11,080 INFO L899 garLoopResultBuilder]: For program point L707-2(lines 707 711) no Hoare annotation was computed. [2022-11-16 10:59:11,080 INFO L895 garLoopResultBuilder]: At program point L864(lines 859 867) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 10:59:11,080 INFO L895 garLoopResultBuilder]: At program point L575(line 575) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) [2022-11-16 10:59:11,080 INFO L899 garLoopResultBuilder]: For program point L575-1(lines 556 580) no Hoare annotation was computed. [2022-11-16 10:59:11,081 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 556 580) no Hoare annotation was computed. [2022-11-16 10:59:11,084 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:59:11,086 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 10:59:11,121 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 10:59:11 BoogieIcfgContainer [2022-11-16 10:59:11,125 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 10:59:11,126 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 10:59:11,127 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 10:59:11,127 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 10:59:11,127 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:58:52" (3/4) ... [2022-11-16 10:59:11,130 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 10:59:11,145 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-16 10:59:11,145 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 10:59:11,145 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 10:59:11,145 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 10:59:11,146 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 10:59:11,146 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:59:11,146 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 10:59:11,146 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 10:59:11,153 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-16 10:59:11,157 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 10:59:11,158 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 10:59:11,158 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 10:59:11,159 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 10:59:11,159 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 10:59:11,159 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 10:59:11,188 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-11-16 10:59:11,188 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == 1 [2022-11-16 10:59:11,189 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((2 <= waterLevel && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == 1) || (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) [2022-11-16 10:59:11,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 10:59:11,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive))) && ((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || 2 <= waterLevel) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) [2022-11-16 10:59:11,193 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || (2 <= waterLevel && 2 <= \result)) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0))) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-11-16 10:59:11,194 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || \result == 0)) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 10:59:11,194 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp)) || !(1 == systemActive)) || \old(waterLevel) < 2) && ((((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) && 2 <= tmp) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || \old(waterLevel) < 2)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((!(waterLevel < 2) && 2 <= \result) && 2 <= tmp)) || !(methaneLevelCritical == 0)) [2022-11-16 10:59:11,194 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || (\result == 0 && \result == 0))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 10:59:11,195 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-16 10:59:11,195 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-16 10:59:11,195 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) [2022-11-16 10:59:11,196 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((pumpRunning == \old(pumpRunning) && tmp == 0) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-16 10:59:11,196 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-16 10:59:11,196 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel) [2022-11-16 10:59:11,200 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) [2022-11-16 10:59:11,254 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 10:59:11,255 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 10:59:11,255 INFO L158 Benchmark]: Toolchain (without parser) took 20277.20ms. Allocated memory was 107.0MB in the beginning and 226.5MB in the end (delta: 119.5MB). Free memory was 60.3MB in the beginning and 77.7MB in the end (delta: -17.4MB). Peak memory consumption was 101.3MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,256 INFO L158 Benchmark]: CDTParser took 0.26ms. Allocated memory is still 107.0MB. Free memory is still 78.1MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 10:59:11,256 INFO L158 Benchmark]: CACSL2BoogieTranslator took 588.91ms. Allocated memory is still 107.0MB. Free memory was 60.1MB in the beginning and 71.6MB in the end (delta: -11.5MB). Peak memory consumption was 4.4MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,256 INFO L158 Benchmark]: Boogie Procedure Inliner took 62.86ms. Allocated memory is still 107.0MB. Free memory was 71.6MB in the beginning and 69.1MB in the end (delta: 2.5MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,257 INFO L158 Benchmark]: Boogie Preprocessor took 58.94ms. Allocated memory is still 107.0MB. Free memory was 69.1MB in the beginning and 67.0MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,258 INFO L158 Benchmark]: RCFGBuilder took 673.71ms. Allocated memory is still 107.0MB. Free memory was 67.0MB in the beginning and 47.5MB in the end (delta: 19.6MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,258 INFO L158 Benchmark]: TraceAbstraction took 18757.05ms. Allocated memory was 107.0MB in the beginning and 226.5MB in the end (delta: 119.5MB). Free memory was 46.8MB in the beginning and 84.0MB in the end (delta: -37.2MB). Peak memory consumption was 105.8MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,259 INFO L158 Benchmark]: Witness Printer took 128.42ms. Allocated memory is still 226.5MB. Free memory was 84.0MB in the beginning and 77.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 10:59:11,261 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.26ms. Allocated memory is still 107.0MB. Free memory is still 78.1MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 588.91ms. Allocated memory is still 107.0MB. Free memory was 60.1MB in the beginning and 71.6MB in the end (delta: -11.5MB). Peak memory consumption was 4.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 62.86ms. Allocated memory is still 107.0MB. Free memory was 71.6MB in the beginning and 69.1MB in the end (delta: 2.5MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 58.94ms. Allocated memory is still 107.0MB. Free memory was 69.1MB in the beginning and 67.0MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 673.71ms. Allocated memory is still 107.0MB. Free memory was 67.0MB in the beginning and 47.5MB in the end (delta: 19.6MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 18757.05ms. Allocated memory was 107.0MB in the beginning and 226.5MB in the end (delta: 119.5MB). Free memory was 46.8MB in the beginning and 84.0MB in the end (delta: -37.2MB). Peak memory consumption was 105.8MB. Max. memory is 16.1GB. * Witness Printer took 128.42ms. Allocated memory is still 226.5MB. Free memory was 84.0MB in the beginning and 77.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 760]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 95 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 18.6s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 8.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3081 SdHoareTripleChecker+Valid, 4.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3052 mSDsluCounter, 4754 SdHoareTripleChecker+Invalid, 3.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3534 mSDsCounter, 1262 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 5504 IncrementalHoareTripleChecker+Invalid, 6766 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1262 mSolverCounterUnsat, 1220 mSDtfsCounter, 5504 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 933 GetRequests, 670 SyntacticMatches, 10 SemanticMatches, 253 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6068 ImplicationChecksByTransitivity, 3.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1331occurred in iteration=11, InterpolantAutomatonStates: 237, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 12 MinimizatonAttempts, 608 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 1916 PreInvPairs, 2121 NumberOfFragments, 1214 HoareAnnotationTreeSize, 1916 FomulaSimplifications, 2459 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 45 FomulaSimplificationsInter, 16749 FormulaSimplificationTreeSizeReductionInter, 3.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 3.0s InterpolantComputationTime, 971 NumberOfCodeBlocks, 971 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1150 ConstructedInterpolants, 0 QuantifiedInterpolants, 2193 SizeOfPredicates, 10 NumberOfNonLiveVariables, 1517 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 17 InterpolantComputations, 10 PerfectInterpolantSequences, 381/420 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 634]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 859]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 582]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive))) && ((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || 2 <= waterLevel) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 732]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 896]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 869]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp)) || !(1 == systemActive)) || \old(waterLevel) < 2) && ((((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) && 2 <= tmp) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || \old(waterLevel) < 2)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((!(waterLevel < 2) && 2 <= \result) && 2 <= tmp)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 746]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 957]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 804]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || \result == 0)) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == 1) || (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) - InvariantResult [Line: 623]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || (\result == 0 && \result == 0))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 739]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 429]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 950]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == 1 - InvariantResult [Line: 967]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 698]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || ((((pumpRunning == \old(pumpRunning) && tmp == 0) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 679]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel) - InvariantResult [Line: 768]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 607]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) - InvariantResult [Line: 845]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) - InvariantResult [Line: 836]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && ((((((tmp == 0 && \result == 0) && \result == 0) || !(1 == systemActive)) || (2 <= waterLevel && 2 <= \result)) || \old(waterLevel) < 2) || !(methaneLevelCritical == 0))) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 756]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 420]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-16 10:59:11,324 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_65c37a38-30d6-4492-b7e9-8d18b786e06f/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE