./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash bd2232848f38516f4fb4022953e113fa5008bf5804c5e85e87585cfa28da0689 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 11:16:31,832 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 11:16:31,837 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 11:16:31,879 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 11:16:31,879 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 11:16:31,883 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 11:16:31,886 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 11:16:31,889 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 11:16:31,891 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 11:16:31,896 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 11:16:31,898 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 11:16:31,899 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 11:16:31,900 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 11:16:31,902 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 11:16:31,904 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 11:16:31,906 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 11:16:31,907 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 11:16:31,908 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 11:16:31,910 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 11:16:31,917 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 11:16:31,919 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 11:16:31,921 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 11:16:31,923 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 11:16:31,924 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 11:16:31,933 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 11:16:31,933 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 11:16:31,933 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 11:16:31,935 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 11:16:31,936 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 11:16:31,937 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 11:16:31,937 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 11:16:31,938 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 11:16:31,943 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 11:16:31,944 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 11:16:31,945 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 11:16:31,946 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 11:16:31,946 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 11:16:31,946 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 11:16:31,947 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 11:16:31,948 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 11:16:31,948 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 11:16:31,949 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 11:16:31,987 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 11:16:32,002 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 11:16:32,004 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 11:16:32,004 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 11:16:32,005 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 11:16:32,005 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 11:16:32,006 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 11:16:32,006 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 11:16:32,006 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 11:16:32,007 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 11:16:32,008 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 11:16:32,008 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 11:16:32,008 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 11:16:32,009 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 11:16:32,009 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 11:16:32,009 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 11:16:32,009 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 11:16:32,010 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 11:16:32,010 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 11:16:32,010 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 11:16:32,010 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 11:16:32,011 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 11:16:32,011 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 11:16:32,011 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 11:16:32,012 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 11:16:32,012 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 11:16:32,012 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 11:16:32,012 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 11:16:32,013 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 11:16:32,013 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 11:16:32,013 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 11:16:32,013 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 11:16:32,014 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 11:16:32,014 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> bd2232848f38516f4fb4022953e113fa5008bf5804c5e85e87585cfa28da0689 [2022-11-16 11:16:32,348 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 11:16:32,383 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 11:16:32,386 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 11:16:32,388 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 11:16:32,388 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 11:16:32,391 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c [2022-11-16 11:16:32,469 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/data/41ffcc638/c57c5090a7df4869895eaa2f23ad5854/FLAGedf008164 [2022-11-16 11:16:33,055 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 11:16:33,055 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c [2022-11-16 11:16:33,087 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/data/41ffcc638/c57c5090a7df4869895eaa2f23ad5854/FLAGedf008164 [2022-11-16 11:16:33,316 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/data/41ffcc638/c57c5090a7df4869895eaa2f23ad5854 [2022-11-16 11:16:33,320 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 11:16:33,322 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 11:16:33,326 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 11:16:33,326 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 11:16:33,329 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 11:16:33,330 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,332 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@15d0fe1c and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33, skipping insertion in model container [2022-11-16 11:16:33,333 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,340 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 11:16:33,395 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 11:16:33,722 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c[18533,18546] [2022-11-16 11:16:33,728 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 11:16:33,740 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 11:16:33,864 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/sv-benchmarks/c/product-lines/minepump_spec4_product54.cil.c[18533,18546] [2022-11-16 11:16:33,866 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 11:16:33,883 INFO L208 MainTranslator]: Completed translation [2022-11-16 11:16:33,884 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33 WrapperNode [2022-11-16 11:16:33,884 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 11:16:33,885 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 11:16:33,886 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 11:16:33,886 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 11:16:33,893 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,922 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,962 INFO L138 Inliner]: procedures = 57, calls = 159, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 284 [2022-11-16 11:16:33,963 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 11:16:33,970 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 11:16:33,971 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 11:16:33,971 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 11:16:33,981 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,981 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,986 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,987 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,993 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,000 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,002 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,004 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,011 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 11:16:34,023 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 11:16:34,024 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 11:16:34,024 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 11:16:34,025 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,031 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 11:16:34,044 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:34,058 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 11:16:34,060 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 11:16:34,098 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 11:16:34,098 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 11:16:34,098 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 11:16:34,098 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 11:16:34,098 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 11:16:34,098 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 11:16:34,099 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 11:16:34,101 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:34,101 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:34,102 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 11:16:34,102 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 11:16:34,103 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:34,103 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:34,103 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-16 11:16:34,103 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-16 11:16:34,103 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 11:16:34,103 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 11:16:34,103 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 11:16:34,103 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 11:16:34,104 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 11:16:34,187 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 11:16:34,189 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 11:16:34,677 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 11:16:34,685 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 11:16:34,685 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 11:16:34,688 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34 BoogieIcfgContainer [2022-11-16 11:16:34,688 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 11:16:34,691 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 11:16:34,691 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 11:16:34,697 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 11:16:34,698 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 11:16:33" (1/3) ... [2022-11-16 11:16:34,698 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@d3b8ccc and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 11:16:34, skipping insertion in model container [2022-11-16 11:16:34,699 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (2/3) ... [2022-11-16 11:16:34,699 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@d3b8ccc and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 11:16:34, skipping insertion in model container [2022-11-16 11:16:34,700 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34" (3/3) ... [2022-11-16 11:16:34,702 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product54.cil.c [2022-11-16 11:16:34,722 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 11:16:34,722 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 11:16:34,800 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 11:16:34,810 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@6bf91604, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 11:16:34,811 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 11:16:34,815 INFO L276 IsEmpty]: Start isEmpty. Operand has 96 states, 72 states have (on average 1.3888888888888888) internal successors, (100), 82 states have internal predecessors, (100), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-16 11:16:34,825 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-16 11:16:34,825 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:34,826 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:34,827 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:34,833 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:34,833 INFO L85 PathProgramCache]: Analyzing trace with hash -1209428772, now seen corresponding path program 1 times [2022-11-16 11:16:34,840 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:34,841 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1385873307] [2022-11-16 11:16:34,841 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:34,842 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:34,985 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,128 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,130 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,130 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1385873307] [2022-11-16 11:16:35,131 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1385873307] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,132 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,133 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 11:16:35,135 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [557993483] [2022-11-16 11:16:35,137 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,142 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 11:16:35,144 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,181 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 11:16:35,182 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 11:16:35,186 INFO L87 Difference]: Start difference. First operand has 96 states, 72 states have (on average 1.3888888888888888) internal successors, (100), 82 states have internal predecessors, (100), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,258 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:35,259 INFO L93 Difference]: Finished difference Result 184 states and 251 transitions. [2022-11-16 11:16:35,259 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 11:16:35,261 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-16 11:16:35,262 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:35,282 INFO L225 Difference]: With dead ends: 184 [2022-11-16 11:16:35,283 INFO L226 Difference]: Without dead ends: 87 [2022-11-16 11:16:35,288 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 11:16:35,292 INFO L413 NwaCegarLoop]: 122 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 122 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:35,293 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:35,312 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 87 states. [2022-11-16 11:16:35,345 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 87 to 87. [2022-11-16 11:16:35,347 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 87 states, 65 states have (on average 1.323076923076923) internal successors, (86), 74 states have internal predecessors, (86), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-16 11:16:35,356 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 87 states to 87 states and 113 transitions. [2022-11-16 11:16:35,359 INFO L78 Accepts]: Start accepts. Automaton has 87 states and 113 transitions. Word has length 19 [2022-11-16 11:16:35,359 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:35,360 INFO L495 AbstractCegarLoop]: Abstraction has 87 states and 113 transitions. [2022-11-16 11:16:35,361 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,361 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 113 transitions. [2022-11-16 11:16:35,367 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-16 11:16:35,367 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,367 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,368 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 11:16:35,369 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,370 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,371 INFO L85 PathProgramCache]: Analyzing trace with hash -560123068, now seen corresponding path program 1 times [2022-11-16 11:16:35,371 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,372 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1103815092] [2022-11-16 11:16:35,372 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,373 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,570 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,570 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,571 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1103815092] [2022-11-16 11:16:35,572 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1103815092] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,572 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,572 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 11:16:35,573 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1228087134] [2022-11-16 11:16:35,573 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,575 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 11:16:35,575 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,576 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 11:16:35,577 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,577 INFO L87 Difference]: Start difference. First operand 87 states and 113 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,609 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:35,611 INFO L93 Difference]: Finished difference Result 139 states and 181 transitions. [2022-11-16 11:16:35,612 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 11:16:35,612 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-16 11:16:35,613 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:35,614 INFO L225 Difference]: With dead ends: 139 [2022-11-16 11:16:35,616 INFO L226 Difference]: Without dead ends: 78 [2022-11-16 11:16:35,617 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,619 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 13 mSDsluCounter, 83 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 183 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:35,622 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 183 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:35,628 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2022-11-16 11:16:35,639 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2022-11-16 11:16:35,643 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.3389830508474576) internal successors, (79), 68 states have internal predecessors, (79), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 11:16:35,644 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 101 transitions. [2022-11-16 11:16:35,645 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 101 transitions. Word has length 20 [2022-11-16 11:16:35,649 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:35,650 INFO L495 AbstractCegarLoop]: Abstraction has 78 states and 101 transitions. [2022-11-16 11:16:35,651 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,651 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 101 transitions. [2022-11-16 11:16:35,652 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-16 11:16:35,653 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,653 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,654 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 11:16:35,654 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,655 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,656 INFO L85 PathProgramCache]: Analyzing trace with hash 1515126443, now seen corresponding path program 1 times [2022-11-16 11:16:35,657 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,658 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2013858988] [2022-11-16 11:16:35,658 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,658 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,682 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,743 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,743 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,743 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2013858988] [2022-11-16 11:16:35,744 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2013858988] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,744 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,744 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 11:16:35,745 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [879837] [2022-11-16 11:16:35,745 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,745 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 11:16:35,745 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,746 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 11:16:35,746 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,747 INFO L87 Difference]: Start difference. First operand 78 states and 101 transitions. Second operand has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,771 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:35,771 INFO L93 Difference]: Finished difference Result 149 states and 196 transitions. [2022-11-16 11:16:35,772 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 11:16:35,772 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-11-16 11:16:35,772 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:35,773 INFO L225 Difference]: With dead ends: 149 [2022-11-16 11:16:35,774 INFO L226 Difference]: Without dead ends: 78 [2022-11-16 11:16:35,775 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,776 INFO L413 NwaCegarLoop]: 99 mSDtfsCounter, 95 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 95 SdHoareTripleChecker+Valid, 99 SdHoareTripleChecker+Invalid, 2 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:35,777 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [95 Valid, 99 Invalid, 2 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:35,778 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2022-11-16 11:16:35,786 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2022-11-16 11:16:35,787 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.3220338983050848) internal successors, (78), 68 states have internal predecessors, (78), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 6 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 11:16:35,787 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 100 transitions. [2022-11-16 11:16:35,788 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 100 transitions. Word has length 25 [2022-11-16 11:16:35,788 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:35,788 INFO L495 AbstractCegarLoop]: Abstraction has 78 states and 100 transitions. [2022-11-16 11:16:35,788 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,789 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 100 transitions. [2022-11-16 11:16:35,790 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2022-11-16 11:16:35,790 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,790 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,791 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 11:16:35,791 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,792 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,792 INFO L85 PathProgramCache]: Analyzing trace with hash -736049444, now seen corresponding path program 1 times [2022-11-16 11:16:35,792 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,792 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [90390245] [2022-11-16 11:16:35,792 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,793 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,812 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,906 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 11:16:35,908 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,910 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,910 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,910 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [90390245] [2022-11-16 11:16:35,911 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [90390245] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,911 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,911 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-16 11:16:35,911 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2138907228] [2022-11-16 11:16:35,911 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,912 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-16 11:16:35,912 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,913 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-16 11:16:35,913 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-16 11:16:35,913 INFO L87 Difference]: Start difference. First operand 78 states and 100 transitions. Second operand has 4 states, 4 states have (on average 7.75) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 11:16:36,116 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:36,117 INFO L93 Difference]: Finished difference Result 220 states and 285 transitions. [2022-11-16 11:16:36,117 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 11:16:36,118 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 7.75) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 34 [2022-11-16 11:16:36,118 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:36,120 INFO L225 Difference]: With dead ends: 220 [2022-11-16 11:16:36,121 INFO L226 Difference]: Without dead ends: 149 [2022-11-16 11:16:36,136 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-16 11:16:36,137 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 137 mSDsluCounter, 108 mSDsCounter, 0 mSdLazyCounter, 72 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 140 SdHoareTripleChecker+Valid, 204 SdHoareTripleChecker+Invalid, 108 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 72 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:36,138 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [140 Valid, 204 Invalid, 108 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 72 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 11:16:36,139 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 149 states. [2022-11-16 11:16:36,159 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 149 to 143. [2022-11-16 11:16:36,160 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 143 states, 110 states have (on average 1.2818181818181817) internal successors, (141), 118 states have internal predecessors, (141), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 11:16:36,161 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 143 states to 143 states and 180 transitions. [2022-11-16 11:16:36,161 INFO L78 Accepts]: Start accepts. Automaton has 143 states and 180 transitions. Word has length 34 [2022-11-16 11:16:36,162 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:36,162 INFO L495 AbstractCegarLoop]: Abstraction has 143 states and 180 transitions. [2022-11-16 11:16:36,162 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 7.75) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 11:16:36,162 INFO L276 IsEmpty]: Start isEmpty. Operand 143 states and 180 transitions. [2022-11-16 11:16:36,163 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-16 11:16:36,164 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:36,164 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:36,164 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 11:16:36,164 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:36,165 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:36,165 INFO L85 PathProgramCache]: Analyzing trace with hash -1212283015, now seen corresponding path program 1 times [2022-11-16 11:16:36,166 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:36,166 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1459798353] [2022-11-16 11:16:36,166 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:36,166 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:36,185 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,347 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:36,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,384 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:36,392 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,421 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:36,422 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:36,422 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1459798353] [2022-11-16 11:16:36,422 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1459798353] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:36,422 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:36,423 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 11:16:36,423 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [779730387] [2022-11-16 11:16:36,423 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:36,423 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:36,424 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:36,424 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:36,424 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 11:16:36,425 INFO L87 Difference]: Start difference. First operand 143 states and 180 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 11:16:36,642 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:36,642 INFO L93 Difference]: Finished difference Result 292 states and 382 transitions. [2022-11-16 11:16:36,644 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 11:16:36,644 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 44 [2022-11-16 11:16:36,644 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:36,650 INFO L225 Difference]: With dead ends: 292 [2022-11-16 11:16:36,650 INFO L226 Difference]: Without dead ends: 156 [2022-11-16 11:16:36,652 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=33, Invalid=57, Unknown=0, NotChecked=0, Total=90 [2022-11-16 11:16:36,657 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 165 mSDsluCounter, 203 mSDsCounter, 0 mSdLazyCounter, 112 mSolverCounterSat, 37 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 167 SdHoareTripleChecker+Valid, 290 SdHoareTripleChecker+Invalid, 149 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 37 IncrementalHoareTripleChecker+Valid, 112 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:36,658 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [167 Valid, 290 Invalid, 149 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [37 Valid, 112 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 11:16:36,660 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 156 states. [2022-11-16 11:16:36,691 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 156 to 145. [2022-11-16 11:16:36,692 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 145 states, 112 states have (on average 1.2767857142857142) internal successors, (143), 120 states have internal predecessors, (143), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 11:16:36,694 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 145 states to 145 states and 182 transitions. [2022-11-16 11:16:36,694 INFO L78 Accepts]: Start accepts. Automaton has 145 states and 182 transitions. Word has length 44 [2022-11-16 11:16:36,694 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:36,695 INFO L495 AbstractCegarLoop]: Abstraction has 145 states and 182 transitions. [2022-11-16 11:16:36,695 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 11:16:36,695 INFO L276 IsEmpty]: Start isEmpty. Operand 145 states and 182 transitions. [2022-11-16 11:16:36,699 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-16 11:16:36,699 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:36,699 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:36,699 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 11:16:36,700 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:36,700 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:36,700 INFO L85 PathProgramCache]: Analyzing trace with hash -191214661, now seen corresponding path program 1 times [2022-11-16 11:16:36,700 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:36,701 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [306882302] [2022-11-16 11:16:36,701 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:36,701 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:36,721 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,807 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:36,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,821 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:36,825 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,854 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:36,854 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:36,854 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [306882302] [2022-11-16 11:16:36,855 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [306882302] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:36,855 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:36,855 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 11:16:36,855 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [349124529] [2022-11-16 11:16:36,855 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:36,856 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:36,856 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:36,856 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:36,856 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 11:16:36,857 INFO L87 Difference]: Start difference. First operand 145 states and 182 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 11:16:37,046 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:37,046 INFO L93 Difference]: Finished difference Result 291 states and 373 transitions. [2022-11-16 11:16:37,047 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 11:16:37,047 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 44 [2022-11-16 11:16:37,049 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:37,051 INFO L225 Difference]: With dead ends: 291 [2022-11-16 11:16:37,051 INFO L226 Difference]: Without dead ends: 153 [2022-11-16 11:16:37,053 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-16 11:16:37,058 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 68 mSDsluCounter, 301 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 392 SdHoareTripleChecker+Invalid, 144 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:37,060 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 392 Invalid, 144 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 11:16:37,061 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 153 states. [2022-11-16 11:16:37,083 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 153 to 148. [2022-11-16 11:16:37,084 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 148 states, 115 states have (on average 1.2695652173913043) internal successors, (146), 123 states have internal predecessors, (146), 14 states have call successors, (14), 13 states have call predecessors, (14), 18 states have return successors, (25), 16 states have call predecessors, (25), 14 states have call successors, (25) [2022-11-16 11:16:37,085 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 148 states to 148 states and 185 transitions. [2022-11-16 11:16:37,085 INFO L78 Accepts]: Start accepts. Automaton has 148 states and 185 transitions. Word has length 44 [2022-11-16 11:16:37,086 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:37,086 INFO L495 AbstractCegarLoop]: Abstraction has 148 states and 185 transitions. [2022-11-16 11:16:37,086 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 11:16:37,086 INFO L276 IsEmpty]: Start isEmpty. Operand 148 states and 185 transitions. [2022-11-16 11:16:37,087 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-16 11:16:37,087 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:37,088 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:37,088 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 11:16:37,088 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:37,088 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:37,089 INFO L85 PathProgramCache]: Analyzing trace with hash 1088539575, now seen corresponding path program 1 times [2022-11-16 11:16:37,089 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:37,089 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1423455547] [2022-11-16 11:16:37,089 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:37,089 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:37,117 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,202 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:37,206 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,219 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:37,222 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,234 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:37,234 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:37,234 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1423455547] [2022-11-16 11:16:37,235 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1423455547] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:37,235 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:37,235 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 11:16:37,235 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [824270344] [2022-11-16 11:16:37,235 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:37,235 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 11:16:37,236 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:37,236 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 11:16:37,236 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 11:16:37,237 INFO L87 Difference]: Start difference. First operand 148 states and 185 transitions. Second operand has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 11:16:37,527 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:37,527 INFO L93 Difference]: Finished difference Result 414 states and 543 transitions. [2022-11-16 11:16:37,528 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 11:16:37,528 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2022-11-16 11:16:37,528 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:37,530 INFO L225 Difference]: With dead ends: 414 [2022-11-16 11:16:37,530 INFO L226 Difference]: Without dead ends: 273 [2022-11-16 11:16:37,531 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-16 11:16:37,532 INFO L413 NwaCegarLoop]: 139 mSDtfsCounter, 202 mSDsluCounter, 182 mSDsCounter, 0 mSdLazyCounter, 170 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 206 SdHoareTripleChecker+Valid, 321 SdHoareTripleChecker+Invalid, 220 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 170 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:37,532 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [206 Valid, 321 Invalid, 220 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 170 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 11:16:37,533 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 273 states. [2022-11-16 11:16:37,558 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 273 to 265. [2022-11-16 11:16:37,559 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 265 states, 204 states have (on average 1.25) internal successors, (255), 216 states have internal predecessors, (255), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-16 11:16:37,560 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 265 states to 265 states and 339 transitions. [2022-11-16 11:16:37,561 INFO L78 Accepts]: Start accepts. Automaton has 265 states and 339 transitions. Word has length 44 [2022-11-16 11:16:37,561 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:37,561 INFO L495 AbstractCegarLoop]: Abstraction has 265 states and 339 transitions. [2022-11-16 11:16:37,561 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 11:16:37,562 INFO L276 IsEmpty]: Start isEmpty. Operand 265 states and 339 transitions. [2022-11-16 11:16:37,562 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2022-11-16 11:16:37,562 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:37,563 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:37,563 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 11:16:37,563 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:37,563 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:37,564 INFO L85 PathProgramCache]: Analyzing trace with hash -1642882216, now seen corresponding path program 1 times [2022-11-16 11:16:37,564 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:37,564 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1648584964] [2022-11-16 11:16:37,564 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:37,564 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:37,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,666 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:37,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,674 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:37,676 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,679 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 11:16:37,680 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,681 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:37,681 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:37,682 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1648584964] [2022-11-16 11:16:37,682 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1648584964] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:37,682 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:37,682 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 11:16:37,682 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1819251365] [2022-11-16 11:16:37,682 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:37,683 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:37,683 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:37,683 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:37,683 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 11:16:37,684 INFO L87 Difference]: Start difference. First operand 265 states and 339 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 11:16:37,926 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:37,926 INFO L93 Difference]: Finished difference Result 523 states and 670 transitions. [2022-11-16 11:16:37,927 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 11:16:37,927 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2022-11-16 11:16:37,927 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:37,929 INFO L225 Difference]: With dead ends: 523 [2022-11-16 11:16:37,929 INFO L226 Difference]: Without dead ends: 265 [2022-11-16 11:16:37,930 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-16 11:16:37,931 INFO L413 NwaCegarLoop]: 85 mSDtfsCounter, 114 mSDsluCounter, 281 mSDsCounter, 0 mSdLazyCounter, 146 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 117 SdHoareTripleChecker+Valid, 366 SdHoareTripleChecker+Invalid, 173 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 146 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:37,931 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [117 Valid, 366 Invalid, 173 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 146 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 11:16:37,932 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 265 states. [2022-11-16 11:16:37,957 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 265 to 263. [2022-11-16 11:16:37,957 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 263 states, 202 states have (on average 1.2425742574257426) internal successors, (251), 214 states have internal predecessors, (251), 29 states have call successors, (29), 28 states have call predecessors, (29), 31 states have return successors, (55), 30 states have call predecessors, (55), 29 states have call successors, (55) [2022-11-16 11:16:37,959 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 263 states to 263 states and 335 transitions. [2022-11-16 11:16:37,959 INFO L78 Accepts]: Start accepts. Automaton has 263 states and 335 transitions. Word has length 46 [2022-11-16 11:16:37,960 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:37,960 INFO L495 AbstractCegarLoop]: Abstraction has 263 states and 335 transitions. [2022-11-16 11:16:37,960 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 11:16:37,960 INFO L276 IsEmpty]: Start isEmpty. Operand 263 states and 335 transitions. [2022-11-16 11:16:37,961 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2022-11-16 11:16:37,961 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:37,961 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:37,961 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 11:16:37,962 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:37,962 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:37,962 INFO L85 PathProgramCache]: Analyzing trace with hash -1115763235, now seen corresponding path program 1 times [2022-11-16 11:16:37,962 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:37,962 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [309570127] [2022-11-16 11:16:37,963 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:37,963 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:37,974 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,071 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:38,072 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,079 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 11:16:38,082 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,098 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:38,100 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,116 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:38,116 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:38,116 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [309570127] [2022-11-16 11:16:38,116 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [309570127] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:38,117 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:38,117 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 11:16:38,117 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1733508236] [2022-11-16 11:16:38,117 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:38,117 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 11:16:38,118 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:38,118 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 11:16:38,118 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 11:16:38,118 INFO L87 Difference]: Start difference. First operand 263 states and 335 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:38,616 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:38,618 INFO L93 Difference]: Finished difference Result 548 states and 721 transitions. [2022-11-16 11:16:38,619 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-16 11:16:38,619 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 48 [2022-11-16 11:16:38,620 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:38,622 INFO L225 Difference]: With dead ends: 548 [2022-11-16 11:16:38,622 INFO L226 Difference]: Without dead ends: 338 [2022-11-16 11:16:38,623 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 54 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-11-16 11:16:38,626 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 193 mSDsluCounter, 353 mSDsCounter, 0 mSdLazyCounter, 459 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 194 SdHoareTripleChecker+Valid, 454 SdHoareTripleChecker+Invalid, 519 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 459 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:38,626 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [194 Valid, 454 Invalid, 519 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 459 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 11:16:38,627 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 338 states. [2022-11-16 11:16:38,656 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 338 to 302. [2022-11-16 11:16:38,657 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 302 states, 233 states have (on average 1.2188841201716738) internal successors, (284), 249 states have internal predecessors, (284), 32 states have call successors, (32), 28 states have call predecessors, (32), 36 states have return successors, (69), 34 states have call predecessors, (69), 32 states have call successors, (69) [2022-11-16 11:16:38,661 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 302 states to 302 states and 385 transitions. [2022-11-16 11:16:38,661 INFO L78 Accepts]: Start accepts. Automaton has 302 states and 385 transitions. Word has length 48 [2022-11-16 11:16:38,661 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:38,662 INFO L495 AbstractCegarLoop]: Abstraction has 302 states and 385 transitions. [2022-11-16 11:16:38,662 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:38,662 INFO L276 IsEmpty]: Start isEmpty. Operand 302 states and 385 transitions. [2022-11-16 11:16:38,664 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 78 [2022-11-16 11:16:38,664 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:38,665 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:38,665 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-16 11:16:38,665 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:38,666 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:38,666 INFO L85 PathProgramCache]: Analyzing trace with hash 1250129477, now seen corresponding path program 1 times [2022-11-16 11:16:38,666 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:38,666 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1169856164] [2022-11-16 11:16:38,667 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:38,667 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:38,708 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,826 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:38,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:38,840 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,853 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:38,855 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,860 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:38,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,866 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2022-11-16 11:16:38,867 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,871 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-11-16 11:16:38,872 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:38,872 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1169856164] [2022-11-16 11:16:38,872 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1169856164] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:38,872 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [896236229] [2022-11-16 11:16:38,873 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:38,873 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:38,873 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:38,879 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:38,908 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 11:16:39,004 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,008 INFO L263 TraceCheckSpWp]: Trace formula consists of 424 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-16 11:16:39,015 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:39,246 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:39,246 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 11:16:39,394 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:39,395 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [896236229] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 11:16:39,395 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 11:16:39,395 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2022-11-16 11:16:39,396 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [851731275] [2022-11-16 11:16:39,396 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 11:16:39,396 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-11-16 11:16:39,397 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:39,397 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-11-16 11:16:39,397 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2022-11-16 11:16:39,398 INFO L87 Difference]: Start difference. First operand 302 states and 385 transitions. Second operand has 12 states, 12 states have (on average 8.583333333333334) internal successors, (103), 9 states have internal predecessors, (103), 3 states have call successors, (12), 6 states have call predecessors, (12), 4 states have return successors, (10), 4 states have call predecessors, (10), 2 states have call successors, (10) [2022-11-16 11:16:41,101 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:41,101 INFO L93 Difference]: Finished difference Result 734 states and 991 transitions. [2022-11-16 11:16:41,102 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 48 states. [2022-11-16 11:16:41,102 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 8.583333333333334) internal successors, (103), 9 states have internal predecessors, (103), 3 states have call successors, (12), 6 states have call predecessors, (12), 4 states have return successors, (10), 4 states have call predecessors, (10), 2 states have call successors, (10) Word has length 77 [2022-11-16 11:16:41,102 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:41,105 INFO L225 Difference]: With dead ends: 734 [2022-11-16 11:16:41,105 INFO L226 Difference]: Without dead ends: 487 [2022-11-16 11:16:41,107 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 228 GetRequests, 171 SyntacticMatches, 6 SemanticMatches, 51 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 834 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=481, Invalid=2275, Unknown=0, NotChecked=0, Total=2756 [2022-11-16 11:16:41,107 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 748 mSDsluCounter, 686 mSDsCounter, 0 mSdLazyCounter, 1209 mSolverCounterSat, 284 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 753 SdHoareTripleChecker+Valid, 796 SdHoareTripleChecker+Invalid, 1493 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 284 IncrementalHoareTripleChecker+Valid, 1209 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:41,108 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [753 Valid, 796 Invalid, 1493 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [284 Valid, 1209 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-11-16 11:16:41,108 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 487 states. [2022-11-16 11:16:41,158 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 487 to 417. [2022-11-16 11:16:41,159 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 417 states, 318 states have (on average 1.2138364779874213) internal successors, (386), 341 states have internal predecessors, (386), 47 states have call successors, (47), 41 states have call predecessors, (47), 51 states have return successors, (107), 46 states have call predecessors, (107), 47 states have call successors, (107) [2022-11-16 11:16:41,161 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 417 states to 417 states and 540 transitions. [2022-11-16 11:16:41,162 INFO L78 Accepts]: Start accepts. Automaton has 417 states and 540 transitions. Word has length 77 [2022-11-16 11:16:41,162 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:41,162 INFO L495 AbstractCegarLoop]: Abstraction has 417 states and 540 transitions. [2022-11-16 11:16:41,162 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 8.583333333333334) internal successors, (103), 9 states have internal predecessors, (103), 3 states have call successors, (12), 6 states have call predecessors, (12), 4 states have return successors, (10), 4 states have call predecessors, (10), 2 states have call successors, (10) [2022-11-16 11:16:41,163 INFO L276 IsEmpty]: Start isEmpty. Operand 417 states and 540 transitions. [2022-11-16 11:16:41,164 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 135 [2022-11-16 11:16:41,165 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:41,165 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:41,171 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-16 11:16:41,370 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-16 11:16:41,370 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:41,371 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:41,371 INFO L85 PathProgramCache]: Analyzing trace with hash -1710488291, now seen corresponding path program 1 times [2022-11-16 11:16:41,371 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:41,371 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1862801723] [2022-11-16 11:16:41,371 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:41,371 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:41,400 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,622 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:41,623 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,631 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:41,636 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,652 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:41,655 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,666 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:41,668 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,680 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-11-16 11:16:41,686 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,789 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 11:16:41,794 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,866 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:41,867 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,870 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:41,871 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,872 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-11-16 11:16:41,875 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,878 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:41,879 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,881 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:41,882 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,883 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 52 proven. 23 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-11-16 11:16:41,884 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:41,884 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1862801723] [2022-11-16 11:16:41,884 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1862801723] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:41,884 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [622812247] [2022-11-16 11:16:41,884 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:41,885 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:41,885 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:41,886 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:41,896 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 11:16:42,026 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:42,029 INFO L263 TraceCheckSpWp]: Trace formula consists of 571 conjuncts, 11 conjunts are in the unsatisfiable core [2022-11-16 11:16:42,033 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:42,261 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 80 proven. 11 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 11:16:42,261 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 11:16:42,588 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 53 proven. 23 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-16 11:16:42,589 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [622812247] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 11:16:42,589 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 11:16:42,589 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 9, 9] total 17 [2022-11-16 11:16:42,589 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [393516612] [2022-11-16 11:16:42,589 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 11:16:42,591 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 17 states [2022-11-16 11:16:42,591 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:42,592 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 17 interpolants. [2022-11-16 11:16:42,592 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=61, Invalid=211, Unknown=0, NotChecked=0, Total=272 [2022-11-16 11:16:42,592 INFO L87 Difference]: Start difference. First operand 417 states and 540 transitions. Second operand has 17 states, 17 states have (on average 8.411764705882353) internal successors, (143), 15 states have internal predecessors, (143), 6 states have call successors, (27), 8 states have call predecessors, (27), 6 states have return successors, (18), 6 states have call predecessors, (18), 6 states have call successors, (18) [2022-11-16 11:16:44,132 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:44,132 INFO L93 Difference]: Finished difference Result 1151 states and 1582 transitions. [2022-11-16 11:16:44,133 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-11-16 11:16:44,133 INFO L78 Accepts]: Start accepts. Automaton has has 17 states, 17 states have (on average 8.411764705882353) internal successors, (143), 15 states have internal predecessors, (143), 6 states have call successors, (27), 8 states have call predecessors, (27), 6 states have return successors, (18), 6 states have call predecessors, (18), 6 states have call successors, (18) Word has length 134 [2022-11-16 11:16:44,134 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:44,139 INFO L225 Difference]: With dead ends: 1151 [2022-11-16 11:16:44,139 INFO L226 Difference]: Without dead ends: 788 [2022-11-16 11:16:44,142 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 332 GetRequests, 289 SyntacticMatches, 6 SemanticMatches, 37 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 309 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=384, Invalid=1098, Unknown=0, NotChecked=0, Total=1482 [2022-11-16 11:16:44,143 INFO L413 NwaCegarLoop]: 147 mSDtfsCounter, 567 mSDsluCounter, 815 mSDsCounter, 0 mSdLazyCounter, 1200 mSolverCounterSat, 274 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 571 SdHoareTripleChecker+Valid, 962 SdHoareTripleChecker+Invalid, 1474 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 274 IncrementalHoareTripleChecker+Valid, 1200 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:44,143 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [571 Valid, 962 Invalid, 1474 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [274 Valid, 1200 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2022-11-16 11:16:44,145 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 788 states. [2022-11-16 11:16:44,227 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 788 to 685. [2022-11-16 11:16:44,228 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 685 states, 518 states have (on average 1.2065637065637065) internal successors, (625), 549 states have internal predecessors, (625), 78 states have call successors, (78), 71 states have call predecessors, (78), 88 states have return successors, (172), 80 states have call predecessors, (172), 78 states have call successors, (172) [2022-11-16 11:16:44,232 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 685 states to 685 states and 875 transitions. [2022-11-16 11:16:44,233 INFO L78 Accepts]: Start accepts. Automaton has 685 states and 875 transitions. Word has length 134 [2022-11-16 11:16:44,234 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:44,234 INFO L495 AbstractCegarLoop]: Abstraction has 685 states and 875 transitions. [2022-11-16 11:16:44,234 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 17 states, 17 states have (on average 8.411764705882353) internal successors, (143), 15 states have internal predecessors, (143), 6 states have call successors, (27), 8 states have call predecessors, (27), 6 states have return successors, (18), 6 states have call predecessors, (18), 6 states have call successors, (18) [2022-11-16 11:16:44,235 INFO L276 IsEmpty]: Start isEmpty. Operand 685 states and 875 transitions. [2022-11-16 11:16:44,238 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 135 [2022-11-16 11:16:44,238 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:44,240 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:44,252 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 11:16:44,447 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:44,447 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:44,448 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:44,448 INFO L85 PathProgramCache]: Analyzing trace with hash -1764881189, now seen corresponding path program 1 times [2022-11-16 11:16:44,448 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:44,448 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1961584568] [2022-11-16 11:16:44,449 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:44,449 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:44,476 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,574 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:44,575 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,583 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 11:16:44,586 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,594 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:44,596 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,598 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,600 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,602 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-11-16 11:16:44,608 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,636 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 11:16:44,641 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,671 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:44,672 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,673 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,677 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,678 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-11-16 11:16:44,680 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,683 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:44,684 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,690 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,691 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,692 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 45 proven. 6 refuted. 0 times theorem prover too weak. 42 trivial. 0 not checked. [2022-11-16 11:16:44,693 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:44,693 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1961584568] [2022-11-16 11:16:44,693 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1961584568] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:44,693 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1541259514] [2022-11-16 11:16:44,693 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:44,694 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:44,694 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:44,695 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:44,719 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 11:16:44,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,837 INFO L263 TraceCheckSpWp]: Trace formula consists of 572 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-16 11:16:44,840 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:44,869 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 29 trivial. 0 not checked. [2022-11-16 11:16:44,872 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 11:16:44,873 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1541259514] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:44,873 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 11:16:44,873 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [8] total 8 [2022-11-16 11:16:44,873 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [627327311] [2022-11-16 11:16:44,874 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:44,874 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 11:16:44,874 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:44,875 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 11:16:44,875 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-11-16 11:16:44,875 INFO L87 Difference]: Start difference. First operand 685 states and 875 transitions. Second operand has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 11:16:44,946 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:44,946 INFO L93 Difference]: Finished difference Result 904 states and 1143 transitions. [2022-11-16 11:16:44,947 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 11:16:44,947 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 134 [2022-11-16 11:16:44,947 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:44,948 INFO L225 Difference]: With dead ends: 904 [2022-11-16 11:16:44,948 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 11:16:44,950 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 165 GetRequests, 157 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=25, Invalid=65, Unknown=0, NotChecked=0, Total=90 [2022-11-16 11:16:44,951 INFO L413 NwaCegarLoop]: 98 mSDtfsCounter, 9 mSDsluCounter, 277 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 375 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:44,951 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 375 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:44,952 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 11:16:44,952 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 11:16:44,952 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:44,952 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 11:16:44,953 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 134 [2022-11-16 11:16:44,953 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:44,953 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 11:16:44,953 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 11:16:44,953 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 11:16:44,954 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 11:16:44,957 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 11:16:44,978 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 11:16:45,163 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-16 11:16:45,165 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 11:16:48,010 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 252 259) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 252 259) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 252 259) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 159 165) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 159 165) the Hoare annotation is: true [2022-11-16 11:16:48,011 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 882 893) the Hoare annotation is: true [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 882 893) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point L886-1(lines 882 893) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L902 garLoopResultBuilder]: At program point L417(lines 392 421) the Hoare annotation is: true [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 392 421) no Hoare annotation was computed. [2022-11-16 11:16:48,011 INFO L899 garLoopResultBuilder]: For program point L413(line 413) no Hoare annotation was computed. [2022-11-16 11:16:48,012 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 392 421) the Hoare annotation is: true [2022-11-16 11:16:48,012 INFO L899 garLoopResultBuilder]: For program point L406(lines 406 410) no Hoare annotation was computed. [2022-11-16 11:16:48,012 INFO L902 garLoopResultBuilder]: At program point L406-1(lines 406 410) the Hoare annotation is: true [2022-11-16 11:16:48,012 INFO L899 garLoopResultBuilder]: For program point L403(line 403) no Hoare annotation was computed. [2022-11-16 11:16:48,012 INFO L902 garLoopResultBuilder]: At program point L402-2(lines 402 416) the Hoare annotation is: true [2022-11-16 11:16:48,012 INFO L902 garLoopResultBuilder]: At program point L398(line 398) the Hoare annotation is: true [2022-11-16 11:16:48,012 INFO L899 garLoopResultBuilder]: For program point L398-1(line 398) no Hoare annotation was computed. [2022-11-16 11:16:48,013 INFO L895 garLoopResultBuilder]: At program point L238(line 238) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-16 11:16:48,013 INFO L895 garLoopResultBuilder]: At program point L238-1(lines 219 243) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (< |old(~waterLevel~0)| 2))) (and (let ((.cse1 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse0 .cse1) .cse2 .cse3 (and (<= 2 ~waterLevel~0) .cse1))) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2 (and .cse0 (= ~waterLevel~0 1))) (or .cse4 .cse2 .cse3 (= |old(~waterLevel~0)| ~waterLevel~0)))) [2022-11-16 11:16:48,013 INFO L895 garLoopResultBuilder]: At program point L267(lines 260 270) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 11:16:48,014 INFO L899 garLoopResultBuilder]: For program point L139-1(lines 138 157) no Hoare annotation was computed. [2022-11-16 11:16:48,014 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 135 158) no Hoare annotation was computed. [2022-11-16 11:16:48,014 INFO L895 garLoopResultBuilder]: At program point L899(lines 894 902) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 11:16:48,014 INFO L899 garLoopResultBuilder]: For program point L862(lines 862 866) no Hoare annotation was computed. [2022-11-16 11:16:48,014 INFO L895 garLoopResultBuilder]: At program point L862-2(lines 858 869) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 11:16:48,015 INFO L895 garLoopResultBuilder]: At program point L276(lines 271 279) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-16 11:16:48,015 INFO L899 garLoopResultBuilder]: For program point L227(lines 227 235) no Hoare annotation was computed. [2022-11-16 11:16:48,015 INFO L899 garLoopResultBuilder]: For program point L223(lines 223 240) no Hoare annotation was computed. [2022-11-16 11:16:48,015 INFO L899 garLoopResultBuilder]: For program point L963(line 963) no Hoare annotation was computed. [2022-11-16 11:16:48,015 INFO L899 garLoopResultBuilder]: For program point L377(lines 377 383) no Hoare annotation was computed. [2022-11-16 11:16:48,015 INFO L899 garLoopResultBuilder]: For program point L373(lines 373 386) no Hoare annotation was computed. [2022-11-16 11:16:48,016 INFO L895 garLoopResultBuilder]: At program point L373-1(lines 365 389) the Hoare annotation is: (let ((.cse5 (<= 2 ~waterLevel~0)) (.cse10 (= 1 ~systemActive~0)) (.cse6 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|))) (let ((.cse2 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse5 .cse10 .cse6 .cse3 .cse8)) (.cse4 (not .cse10)) (.cse9 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (and .cse2 .cse3) .cse4 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse4 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (let ((.cse7 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse5 .cse6 .cse7 .cse8) .cse4 .cse9 (and .cse2 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) .cse7 (<= 1 |timeShift_getWaterLevel_#res#1|)))) (or .cse0 .cse1 .cse4 .cse9)))) [2022-11-16 11:16:48,016 INFO L899 garLoopResultBuilder]: For program point L146-1(lines 146 152) no Hoare annotation was computed. [2022-11-16 11:16:48,016 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 135 158) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-16 11:16:48,017 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 135 158) no Hoare annotation was computed. [2022-11-16 11:16:48,017 INFO L895 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 11:16:48,017 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 963) no Hoare annotation was computed. [2022-11-16 11:16:48,017 INFO L895 garLoopResultBuilder]: At program point L229(line 229) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-16 11:16:48,018 INFO L895 garLoopResultBuilder]: At program point L964(lines 959 966) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-16 11:16:48,018 INFO L895 garLoopResultBuilder]: At program point L931(lines 926 934) the Hoare annotation is: (let ((.cse3 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (< |old(~waterLevel~0)| 2)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse3)) (let ((.cse4 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and (<= 2 ~waterLevel~0) .cse4 .cse3) .cse1 .cse2 (and .cse5 .cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse5 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-16 11:16:48,018 INFO L899 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2022-11-16 11:16:48,018 INFO L899 garLoopResultBuilder]: For program point L85-1(lines 85 91) no Hoare annotation was computed. [2022-11-16 11:16:48,018 INFO L895 garLoopResultBuilder]: At program point L110(lines 65 112) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 11:16:48,019 INFO L895 garLoopResultBuilder]: At program point L77(line 77) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 11:16:48,019 INFO L895 garLoopResultBuilder]: At program point L998(lines 993 1001) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:48,019 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 11:16:48,019 INFO L895 garLoopResultBuilder]: At program point L990(lines 986 992) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:48,019 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 11:16:48,020 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 11:16:48,020 INFO L895 garLoopResultBuilder]: At program point L359(lines 354 361) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 11:16:48,020 INFO L899 garLoopResultBuilder]: For program point L103(lines 103 107) no Hoare annotation was computed. [2022-11-16 11:16:48,020 INFO L895 garLoopResultBuilder]: At program point L103-2(lines 95 108) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 11:16:48,020 INFO L895 garLoopResultBuilder]: At program point L450(lines 446 452) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:48,021 INFO L899 garLoopResultBuilder]: For program point L66(lines 65 112) no Hoare annotation was computed. [2022-11-16 11:16:48,021 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 11:16:48,021 INFO L899 garLoopResultBuilder]: For program point L95(lines 95 108) no Hoare annotation was computed. [2022-11-16 11:16:48,021 INFO L895 garLoopResultBuilder]: At program point L983(lines 979 985) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:48,021 INFO L895 garLoopResultBuilder]: At program point L87(line 87) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 11:16:48,022 INFO L902 garLoopResultBuilder]: At program point L116(lines 55 120) the Hoare annotation is: true [2022-11-16 11:16:48,022 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 81) no Hoare annotation was computed. [2022-11-16 11:16:48,022 INFO L899 garLoopResultBuilder]: For program point L75-1(lines 75 81) no Hoare annotation was computed. [2022-11-16 11:16:48,022 INFO L899 garLoopResultBuilder]: For program point L67(lines 67 71) no Hoare annotation was computed. [2022-11-16 11:16:48,022 INFO L899 garLoopResultBuilder]: For program point L476(lines 476 483) no Hoare annotation was computed. [2022-11-16 11:16:48,022 INFO L899 garLoopResultBuilder]: For program point L476-2(lines 476 483) no Hoare annotation was computed. [2022-11-16 11:16:48,023 INFO L895 garLoopResultBuilder]: At program point L113(lines 64 114) the Hoare annotation is: false [2022-11-16 11:16:48,023 INFO L902 garLoopResultBuilder]: At program point L460(lines 453 462) the Hoare annotation is: true [2022-11-16 11:16:48,023 INFO L902 garLoopResultBuilder]: At program point L485(lines 466 488) the Hoare annotation is: true [2022-11-16 11:16:48,023 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 167 191) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 11:16:48,023 INFO L895 garLoopResultBuilder]: At program point L186(line 186) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 11:16:48,024 INFO L899 garLoopResultBuilder]: For program point L186-1(lines 167 191) no Hoare annotation was computed. [2022-11-16 11:16:48,024 INFO L895 garLoopResultBuilder]: At program point L944(lines 935 948) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (<= 2 ~waterLevel~0)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0))) [2022-11-16 11:16:48,024 INFO L895 garLoopResultBuilder]: At program point L331(lines 316 334) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 (not (<= 1 ~waterLevel~0))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0))))) [2022-11-16 11:16:48,024 INFO L899 garLoopResultBuilder]: For program point L325(lines 325 329) no Hoare annotation was computed. [2022-11-16 11:16:48,024 INFO L899 garLoopResultBuilder]: For program point L325-2(lines 325 329) no Hoare annotation was computed. [2022-11-16 11:16:48,025 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 167 191) no Hoare annotation was computed. [2022-11-16 11:16:48,025 INFO L895 garLoopResultBuilder]: At program point L249(lines 244 251) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-11-16 11:16:48,025 INFO L895 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (let ((.cse3 (= 1 ~systemActive~0))) (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) .cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse3))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2))))) [2022-11-16 11:16:48,025 INFO L899 garLoopResultBuilder]: For program point L175(lines 175 183) no Hoare annotation was computed. [2022-11-16 11:16:48,025 INFO L899 garLoopResultBuilder]: For program point L171(lines 171 188) no Hoare annotation was computed. [2022-11-16 11:16:48,026 INFO L899 garLoopResultBuilder]: For program point L939(lines 939 945) no Hoare annotation was computed. [2022-11-16 11:16:48,026 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 870 881) no Hoare annotation was computed. [2022-11-16 11:16:48,026 INFO L899 garLoopResultBuilder]: For program point L874-1(lines 870 881) no Hoare annotation was computed. [2022-11-16 11:16:48,026 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 870 881) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 11:16:48,026 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 193 217) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 11:16:48,027 INFO L895 garLoopResultBuilder]: At program point L954(lines 949 957) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 11:16:48,027 INFO L895 garLoopResultBuilder]: At program point L207(line 207) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 11:16:48,027 INFO L895 garLoopResultBuilder]: At program point L203(line 203) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))))) [2022-11-16 11:16:48,027 INFO L899 garLoopResultBuilder]: For program point L201(lines 201 209) no Hoare annotation was computed. [2022-11-16 11:16:48,027 INFO L899 garLoopResultBuilder]: For program point L197(lines 197 214) no Hoare annotation was computed. [2022-11-16 11:16:48,028 INFO L895 garLoopResultBuilder]: At program point L350(lines 335 353) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~waterLevel~0)))) (and (or (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 11:16:48,028 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 193 217) no Hoare annotation was computed. [2022-11-16 11:16:48,028 INFO L899 garLoopResultBuilder]: For program point L344(lines 344 348) no Hoare annotation was computed. [2022-11-16 11:16:48,028 INFO L899 garLoopResultBuilder]: For program point L344-2(lines 344 348) no Hoare annotation was computed. [2022-11-16 11:16:48,028 INFO L895 garLoopResultBuilder]: At program point L212(line 212) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) [2022-11-16 11:16:48,029 INFO L899 garLoopResultBuilder]: For program point L212-1(lines 193 217) no Hoare annotation was computed. [2022-11-16 11:16:48,032 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:48,034 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 11:16:48,057 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 11:16:48 BoogieIcfgContainer [2022-11-16 11:16:48,057 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 11:16:48,058 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 11:16:48,058 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 11:16:48,058 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 11:16:48,059 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34" (3/4) ... [2022-11-16 11:16:48,062 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 11:16:48,068 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-16 11:16:48,068 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 11:16:48,068 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 11:16:48,068 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 11:16:48,068 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 11:16:48,069 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:48,069 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 11:16:48,069 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:48,076 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-16 11:16:48,077 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 11:16:48,077 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 11:16:48,078 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 11:16:48,078 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 11:16:48,079 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 11:16:48,079 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 11:16:48,104 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 11:16:48,104 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) [2022-11-16 11:16:48,105 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-11-16 11:16:48,105 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 11:16:48,106 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && ((((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || \old(waterLevel) < 2) [2022-11-16 11:16:48,106 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-16 11:16:48,106 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-16 11:16:48,106 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-16 11:16:48,107 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (pumpRunning == 0 && 2 <= waterLevel)) || (1 <= \result && pumpRunning == 0) [2022-11-16 11:16:48,107 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((tmp == 0 && pumpRunning == \old(pumpRunning)) && 1 <= \result) && 1 <= tmp___0) && \result == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) [2022-11-16 11:16:48,107 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-16 11:16:48,108 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (tmp___0 == 0 && \result == 0)) [2022-11-16 11:16:48,108 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) [2022-11-16 11:16:48,139 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 11:16:48,139 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 11:16:48,140 INFO L158 Benchmark]: Toolchain (without parser) took 14817.22ms. Allocated memory was 119.5MB in the beginning and 226.5MB in the end (delta: 107.0MB). Free memory was 75.9MB in the beginning and 88.3MB in the end (delta: -12.4MB). Peak memory consumption was 94.3MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,140 INFO L158 Benchmark]: CDTParser took 0.36ms. Allocated memory is still 119.5MB. Free memory is still 93.1MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 11:16:48,140 INFO L158 Benchmark]: CACSL2BoogieTranslator took 558.86ms. Allocated memory is still 119.5MB. Free memory was 75.7MB in the beginning and 84.8MB in the end (delta: -9.1MB). Peak memory consumption was 8.5MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,141 INFO L158 Benchmark]: Boogie Procedure Inliner took 78.18ms. Allocated memory is still 119.5MB. Free memory was 84.8MB in the beginning and 82.1MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,141 INFO L158 Benchmark]: Boogie Preprocessor took 52.48ms. Allocated memory is still 119.5MB. Free memory was 82.1MB in the beginning and 80.3MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,142 INFO L158 Benchmark]: RCFGBuilder took 665.07ms. Allocated memory is still 119.5MB. Free memory was 80.3MB in the beginning and 60.6MB in the end (delta: 19.7MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,142 INFO L158 Benchmark]: TraceAbstraction took 13366.65ms. Allocated memory was 119.5MB in the beginning and 226.5MB in the end (delta: 107.0MB). Free memory was 60.0MB in the beginning and 93.5MB in the end (delta: -33.5MB). Peak memory consumption was 98.2MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,143 INFO L158 Benchmark]: Witness Printer took 81.16ms. Allocated memory is still 226.5MB. Free memory was 93.5MB in the beginning and 88.3MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-16 11:16:48,144 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.36ms. Allocated memory is still 119.5MB. Free memory is still 93.1MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 558.86ms. Allocated memory is still 119.5MB. Free memory was 75.7MB in the beginning and 84.8MB in the end (delta: -9.1MB). Peak memory consumption was 8.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 78.18ms. Allocated memory is still 119.5MB. Free memory was 84.8MB in the beginning and 82.1MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 52.48ms. Allocated memory is still 119.5MB. Free memory was 82.1MB in the beginning and 80.3MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 665.07ms. Allocated memory is still 119.5MB. Free memory was 80.3MB in the beginning and 60.6MB in the end (delta: 19.7MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 13366.65ms. Allocated memory was 119.5MB in the beginning and 226.5MB in the end (delta: 107.0MB). Free memory was 60.0MB in the beginning and 93.5MB in the end (delta: -33.5MB). Peak memory consumption was 98.2MB. Max. memory is 16.1GB. * Witness Printer took 81.16ms. Allocated memory is still 226.5MB. Free memory was 93.5MB in the beginning and 88.3MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 963]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 96 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 13.3s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 5.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2337 SdHoareTripleChecker+Valid, 3.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2311 mSDsluCounter, 4564 SdHoareTripleChecker+Invalid, 2.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3289 mSDsCounter, 794 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3506 IncrementalHoareTripleChecker+Invalid, 4300 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 794 mSolverCounterUnsat, 1275 mSDtfsCounter, 3506 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 827 GetRequests, 666 SyntacticMatches, 15 SemanticMatches, 146 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1213 ImplicationChecksByTransitivity, 1.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=685occurred in iteration=11, InterpolantAutomatonStates: 142, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 12 MinimizatonAttempts, 241 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 46 LocationsWithAnnotation, 1311 PreInvPairs, 1420 NumberOfFragments, 1052 HoareAnnotationTreeSize, 1311 FomulaSimplifications, 1047 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 46 FomulaSimplificationsInter, 5807 FormulaSimplificationTreeSizeReductionInter, 2.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 3.0s InterpolantComputationTime, 1014 NumberOfCodeBlocks, 1014 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1208 ConstructedInterpolants, 0 QuantifiedInterpolants, 2229 SizeOfPredicates, 10 NumberOfNonLiveVariables, 1567 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 17 InterpolantComputations, 10 PerfectInterpolantSequences, 444/516 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 979]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 993]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 65]: Loop Invariant Derived loop invariant: ((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 365]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && ((((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((pumpRunning == 0 && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || \old(waterLevel) < 2) - InvariantResult [Line: 935]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) || (pumpRunning == 0 && 2 <= waterLevel)) || (1 <= \result && pumpRunning == 0) - InvariantResult [Line: 959]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (tmp___0 == 0 && \result == 0)) - InvariantResult [Line: 949]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= waterLevel)) || (pumpRunning == \old(pumpRunning) && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 926]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (\old(waterLevel) == waterLevel && 2 <= \result)) && (((((2 <= waterLevel && \old(waterLevel) <= waterLevel + 1) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) && 1 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 335]: Loop Invariant Derived loop invariant: ((((((tmp == 0 && pumpRunning == \old(pumpRunning)) && 1 <= \result) && 1 <= tmp___0) && \result == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= waterLevel)) - InvariantResult [Line: 858]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 271]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 260]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 894]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 453]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 354]: Loop Invariant Derived loop invariant: ((!(waterLevel < 2) && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 244]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) - InvariantResult [Line: 446]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 466]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 986]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 55]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 402]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 219]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) || (2 <= waterLevel && \old(waterLevel) <= waterLevel + 1)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-16 11:16:48,196 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_bb7a641a-0d6e-4b38-995b-589f90ebd268/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE