./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 1741a5d4e19b6faba6ff51056891b76c8b4c0acd4f550f71706571820842dcfa --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 11:16:31,772 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 11:16:31,777 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 11:16:31,806 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 11:16:31,806 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 11:16:31,807 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 11:16:31,809 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 11:16:31,811 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 11:16:31,812 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 11:16:31,814 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 11:16:31,815 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 11:16:31,816 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 11:16:31,817 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 11:16:31,818 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 11:16:31,819 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 11:16:31,820 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 11:16:31,821 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 11:16:31,822 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 11:16:31,824 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 11:16:31,826 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 11:16:31,828 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 11:16:31,829 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 11:16:31,830 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 11:16:31,831 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 11:16:31,835 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 11:16:31,836 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 11:16:31,836 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 11:16:31,837 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 11:16:31,838 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 11:16:31,839 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 11:16:31,839 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 11:16:31,840 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 11:16:31,841 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 11:16:31,842 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 11:16:31,843 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 11:16:31,844 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 11:16:31,845 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 11:16:31,845 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 11:16:31,845 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 11:16:31,847 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 11:16:31,847 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 11:16:31,850 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 11:16:31,892 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 11:16:31,892 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 11:16:31,892 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 11:16:31,893 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 11:16:31,893 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 11:16:31,894 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 11:16:31,894 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 11:16:31,895 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 11:16:31,895 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 11:16:31,895 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 11:16:31,895 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 11:16:31,896 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 11:16:31,896 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 11:16:31,896 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 11:16:31,896 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 11:16:31,896 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 11:16:31,897 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 11:16:31,897 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 11:16:31,897 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 11:16:31,897 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 11:16:31,898 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 11:16:31,898 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 11:16:31,898 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 11:16:31,898 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 11:16:31,899 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 11:16:31,899 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 11:16:31,899 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 11:16:31,899 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 11:16:31,900 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 11:16:31,900 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 11:16:31,900 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 11:16:31,900 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 11:16:31,901 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 11:16:31,901 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 1741a5d4e19b6faba6ff51056891b76c8b4c0acd4f550f71706571820842dcfa [2022-11-16 11:16:32,186 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 11:16:32,212 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 11:16:32,215 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 11:16:32,216 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 11:16:32,217 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 11:16:32,219 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c [2022-11-16 11:16:32,295 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/data/a64a559c1/d1f5ba2ff623422e972374389b297fc9/FLAG0169e927d [2022-11-16 11:16:32,900 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 11:16:32,901 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c [2022-11-16 11:16:32,915 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/data/a64a559c1/d1f5ba2ff623422e972374389b297fc9/FLAG0169e927d [2022-11-16 11:16:33,186 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/data/a64a559c1/d1f5ba2ff623422e972374389b297fc9 [2022-11-16 11:16:33,188 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 11:16:33,190 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 11:16:33,199 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 11:16:33,199 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 11:16:33,203 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 11:16:33,204 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,206 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1b6d508f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33, skipping insertion in model container [2022-11-16 11:16:33,206 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,214 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 11:16:33,260 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 11:16:33,643 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c[6887,6900] [2022-11-16 11:16:33,785 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 11:16:33,803 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 11:16:33,866 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/sv-benchmarks/c/product-lines/minepump_spec4_product55.cil.c[6887,6900] [2022-11-16 11:16:33,927 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 11:16:33,948 INFO L208 MainTranslator]: Completed translation [2022-11-16 11:16:33,949 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33 WrapperNode [2022-11-16 11:16:33,949 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 11:16:33,951 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 11:16:33,951 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 11:16:33,951 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 11:16:33,961 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:33,989 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,044 INFO L138 Inliner]: procedures = 57, calls = 160, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 286 [2022-11-16 11:16:34,044 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 11:16:34,045 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 11:16:34,045 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 11:16:34,046 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 11:16:34,057 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,057 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,060 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,060 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,066 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,072 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,074 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,076 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,079 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 11:16:34,080 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 11:16:34,080 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 11:16:34,080 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 11:16:34,082 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (1/1) ... [2022-11-16 11:16:34,100 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 11:16:34,129 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:34,165 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 11:16:34,197 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 11:16:34,222 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 11:16:34,223 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 11:16:34,223 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 11:16:34,223 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 11:16:34,223 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 11:16:34,224 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 11:16:34,224 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 11:16:34,226 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:34,226 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:34,226 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 11:16:34,226 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 11:16:34,227 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:34,227 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:34,227 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-16 11:16:34,227 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-16 11:16:34,228 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 11:16:34,228 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 11:16:34,228 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 11:16:34,229 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 11:16:34,229 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 11:16:34,360 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 11:16:34,362 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 11:16:34,845 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 11:16:34,860 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 11:16:34,861 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 11:16:34,863 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34 BoogieIcfgContainer [2022-11-16 11:16:34,864 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 11:16:34,866 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 11:16:34,867 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 11:16:34,871 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 11:16:34,871 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 11:16:33" (1/3) ... [2022-11-16 11:16:34,872 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@373c80a1 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 11:16:34, skipping insertion in model container [2022-11-16 11:16:34,873 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 11:16:33" (2/3) ... [2022-11-16 11:16:34,873 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@373c80a1 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 11:16:34, skipping insertion in model container [2022-11-16 11:16:34,873 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34" (3/3) ... [2022-11-16 11:16:34,875 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product55.cil.c [2022-11-16 11:16:34,916 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 11:16:34,916 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 11:16:35,020 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 11:16:35,028 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4f537702, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 11:16:35,028 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 11:16:35,037 INFO L276 IsEmpty]: Start isEmpty. Operand has 99 states, 74 states have (on average 1.3918918918918919) internal successors, (103), 85 states have internal predecessors, (103), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2022-11-16 11:16:35,050 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-16 11:16:35,050 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,051 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,051 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,057 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,058 INFO L85 PathProgramCache]: Analyzing trace with hash -405346600, now seen corresponding path program 1 times [2022-11-16 11:16:35,067 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,067 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1791519854] [2022-11-16 11:16:35,068 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,068 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,256 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,370 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,375 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,375 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1791519854] [2022-11-16 11:16:35,376 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1791519854] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,376 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,377 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 11:16:35,379 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1669068994] [2022-11-16 11:16:35,380 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,385 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 11:16:35,387 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,431 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 11:16:35,432 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 11:16:35,437 INFO L87 Difference]: Start difference. First operand has 99 states, 74 states have (on average 1.3918918918918919) internal successors, (103), 85 states have internal predecessors, (103), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,520 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:35,521 INFO L93 Difference]: Finished difference Result 190 states and 261 transitions. [2022-11-16 11:16:35,523 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 11:16:35,525 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-16 11:16:35,525 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:35,540 INFO L225 Difference]: With dead ends: 190 [2022-11-16 11:16:35,540 INFO L226 Difference]: Without dead ends: 90 [2022-11-16 11:16:35,547 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 11:16:35,551 INFO L413 NwaCegarLoop]: 127 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 127 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:35,552 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 127 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:35,575 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 90 states. [2022-11-16 11:16:35,602 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 90 to 90. [2022-11-16 11:16:35,604 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 90 states, 67 states have (on average 1.328358208955224) internal successors, (89), 77 states have internal predecessors, (89), 15 states have call successors, (15), 8 states have call predecessors, (15), 7 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-16 11:16:35,607 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 90 states to 90 states and 118 transitions. [2022-11-16 11:16:35,609 INFO L78 Accepts]: Start accepts. Automaton has 90 states and 118 transitions. Word has length 19 [2022-11-16 11:16:35,609 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:35,609 INFO L495 AbstractCegarLoop]: Abstraction has 90 states and 118 transitions. [2022-11-16 11:16:35,610 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,610 INFO L276 IsEmpty]: Start isEmpty. Operand 90 states and 118 transitions. [2022-11-16 11:16:35,612 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-16 11:16:35,612 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,613 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,613 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 11:16:35,613 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,614 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,615 INFO L85 PathProgramCache]: Analyzing trace with hash 1370466006, now seen corresponding path program 1 times [2022-11-16 11:16:35,615 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,615 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [258496982] [2022-11-16 11:16:35,615 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,616 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,654 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:35,792 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:35,792 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:35,792 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [258496982] [2022-11-16 11:16:35,793 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [258496982] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:35,793 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:35,793 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 11:16:35,793 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [162496125] [2022-11-16 11:16:35,794 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:35,795 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 11:16:35,795 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:35,796 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 11:16:35,796 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,797 INFO L87 Difference]: Start difference. First operand 90 states and 118 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,832 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:35,832 INFO L93 Difference]: Finished difference Result 142 states and 186 transitions. [2022-11-16 11:16:35,833 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 11:16:35,833 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-16 11:16:35,834 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:35,835 INFO L225 Difference]: With dead ends: 142 [2022-11-16 11:16:35,835 INFO L226 Difference]: Without dead ends: 81 [2022-11-16 11:16:35,836 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:35,838 INFO L413 NwaCegarLoop]: 105 mSDtfsCounter, 16 mSDsluCounter, 84 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 189 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:35,838 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 189 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:35,840 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 81 states. [2022-11-16 11:16:35,851 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 81 to 81. [2022-11-16 11:16:35,852 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 81 states, 61 states have (on average 1.3442622950819672) internal successors, (82), 71 states have internal predecessors, (82), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 7 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-16 11:16:35,853 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 81 states to 81 states and 106 transitions. [2022-11-16 11:16:35,854 INFO L78 Accepts]: Start accepts. Automaton has 81 states and 106 transitions. Word has length 20 [2022-11-16 11:16:35,854 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:35,854 INFO L495 AbstractCegarLoop]: Abstraction has 81 states and 106 transitions. [2022-11-16 11:16:35,854 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:35,855 INFO L276 IsEmpty]: Start isEmpty. Operand 81 states and 106 transitions. [2022-11-16 11:16:35,856 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-16 11:16:35,856 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:35,856 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:35,856 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 11:16:35,857 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:35,857 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:35,858 INFO L85 PathProgramCache]: Analyzing trace with hash 412043634, now seen corresponding path program 1 times [2022-11-16 11:16:35,858 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:35,858 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [456929798] [2022-11-16 11:16:35,858 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:35,859 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:35,908 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,221 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:36,222 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:36,222 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [456929798] [2022-11-16 11:16:36,261 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [456929798] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:36,261 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:36,262 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 11:16:36,262 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1429698562] [2022-11-16 11:16:36,262 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:36,263 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:36,263 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:36,264 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:36,264 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-16 11:16:36,264 INFO L87 Difference]: Start difference. First operand 81 states and 106 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:36,617 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:36,617 INFO L93 Difference]: Finished difference Result 266 states and 355 transitions. [2022-11-16 11:16:36,618 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-16 11:16:36,618 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-11-16 11:16:36,619 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:36,621 INFO L225 Difference]: With dead ends: 266 [2022-11-16 11:16:36,621 INFO L226 Difference]: Without dead ends: 192 [2022-11-16 11:16:36,623 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-16 11:16:36,624 INFO L413 NwaCegarLoop]: 137 mSDtfsCounter, 219 mSDsluCounter, 391 mSDsCounter, 0 mSdLazyCounter, 113 mSolverCounterSat, 14 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 219 SdHoareTripleChecker+Valid, 528 SdHoareTripleChecker+Invalid, 127 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 14 IncrementalHoareTripleChecker+Valid, 113 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:36,625 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [219 Valid, 528 Invalid, 127 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [14 Valid, 113 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 11:16:36,627 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 192 states. [2022-11-16 11:16:36,695 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 192 to 186. [2022-11-16 11:16:36,698 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 186 states, 139 states have (on average 1.3741007194244603) internal successors, (191), 161 states have internal predecessors, (191), 28 states have call successors, (28), 18 states have call predecessors, (28), 18 states have return successors, (29), 16 states have call predecessors, (29), 28 states have call successors, (29) [2022-11-16 11:16:36,703 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 186 states to 186 states and 248 transitions. [2022-11-16 11:16:36,706 INFO L78 Accepts]: Start accepts. Automaton has 186 states and 248 transitions. Word has length 24 [2022-11-16 11:16:36,708 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:36,709 INFO L495 AbstractCegarLoop]: Abstraction has 186 states and 248 transitions. [2022-11-16 11:16:36,709 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:36,710 INFO L276 IsEmpty]: Start isEmpty. Operand 186 states and 248 transitions. [2022-11-16 11:16:36,711 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-16 11:16:36,713 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:36,714 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:36,714 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 11:16:36,715 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:36,715 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:36,721 INFO L85 PathProgramCache]: Analyzing trace with hash 2062247464, now seen corresponding path program 1 times [2022-11-16 11:16:36,722 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:36,722 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [393100700] [2022-11-16 11:16:36,722 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:36,723 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:36,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:36,894 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:36,895 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:36,895 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [393100700] [2022-11-16 11:16:36,895 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [393100700] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:36,896 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:36,896 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-16 11:16:36,896 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1575028648] [2022-11-16 11:16:36,896 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:36,897 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 11:16:36,897 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:36,897 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 11:16:36,897 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 11:16:36,898 INFO L87 Difference]: Start difference. First operand 186 states and 248 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:37,057 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:37,058 INFO L93 Difference]: Finished difference Result 527 states and 733 transitions. [2022-11-16 11:16:37,059 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 11:16:37,059 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-11-16 11:16:37,060 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:37,072 INFO L225 Difference]: With dead ends: 527 [2022-11-16 11:16:37,072 INFO L226 Difference]: Without dead ends: 348 [2022-11-16 11:16:37,076 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-16 11:16:37,077 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 77 mSDsluCounter, 315 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 77 SdHoareTripleChecker+Valid, 426 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:37,078 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [77 Valid, 426 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 11:16:37,079 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 348 states. [2022-11-16 11:16:37,160 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 348 to 348. [2022-11-16 11:16:37,161 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 348 states, 258 states have (on average 1.3488372093023255) internal successors, (348), 298 states have internal predecessors, (348), 56 states have call successors, (56), 36 states have call predecessors, (56), 33 states have return successors, (62), 29 states have call predecessors, (62), 56 states have call successors, (62) [2022-11-16 11:16:37,164 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 348 states to 348 states and 466 transitions. [2022-11-16 11:16:37,164 INFO L78 Accepts]: Start accepts. Automaton has 348 states and 466 transitions. Word has length 28 [2022-11-16 11:16:37,164 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:37,165 INFO L495 AbstractCegarLoop]: Abstraction has 348 states and 466 transitions. [2022-11-16 11:16:37,165 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:37,165 INFO L276 IsEmpty]: Start isEmpty. Operand 348 states and 466 transitions. [2022-11-16 11:16:37,167 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-11-16 11:16:37,172 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:37,172 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:37,173 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 11:16:37,173 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:37,174 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:37,174 INFO L85 PathProgramCache]: Analyzing trace with hash -1056507795, now seen corresponding path program 1 times [2022-11-16 11:16:37,174 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:37,174 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1422324352] [2022-11-16 11:16:37,175 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:37,175 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:37,198 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,328 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:37,329 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:37,330 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1422324352] [2022-11-16 11:16:37,330 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1422324352] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:37,330 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:37,330 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 11:16:37,332 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [508222839] [2022-11-16 11:16:37,333 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:37,334 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 11:16:37,334 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:37,334 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 11:16:37,335 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:37,335 INFO L87 Difference]: Start difference. First operand 348 states and 466 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:37,431 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:37,432 INFO L93 Difference]: Finished difference Result 794 states and 1093 transitions. [2022-11-16 11:16:37,436 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 11:16:37,436 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-11-16 11:16:37,437 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:37,443 INFO L225 Difference]: With dead ends: 794 [2022-11-16 11:16:37,444 INFO L226 Difference]: Without dead ends: 453 [2022-11-16 11:16:37,446 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 11:16:37,457 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 58 mSDsluCounter, 68 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 58 SdHoareTripleChecker+Valid, 177 SdHoareTripleChecker+Invalid, 23 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:37,459 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [58 Valid, 177 Invalid, 23 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:37,461 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 453 states. [2022-11-16 11:16:37,524 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 453 to 442. [2022-11-16 11:16:37,525 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 442 states, 336 states have (on average 1.2916666666666667) internal successors, (434), 361 states have internal predecessors, (434), 55 states have call successors, (55), 51 states have call predecessors, (55), 50 states have return successors, (83), 49 states have call predecessors, (83), 55 states have call successors, (83) [2022-11-16 11:16:37,528 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 442 states to 442 states and 572 transitions. [2022-11-16 11:16:37,529 INFO L78 Accepts]: Start accepts. Automaton has 442 states and 572 transitions. Word has length 30 [2022-11-16 11:16:37,529 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:37,530 INFO L495 AbstractCegarLoop]: Abstraction has 442 states and 572 transitions. [2022-11-16 11:16:37,530 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:37,530 INFO L276 IsEmpty]: Start isEmpty. Operand 442 states and 572 transitions. [2022-11-16 11:16:37,532 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-16 11:16:37,532 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:37,532 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:37,532 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 11:16:37,533 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:37,533 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:37,534 INFO L85 PathProgramCache]: Analyzing trace with hash -1410993586, now seen corresponding path program 1 times [2022-11-16 11:16:37,534 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:37,534 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1256069522] [2022-11-16 11:16:37,535 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:37,535 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:37,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,685 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:37,687 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:37,693 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:37,695 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:37,696 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1256069522] [2022-11-16 11:16:37,696 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1256069522] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:37,696 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:37,696 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 11:16:37,697 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [110013900] [2022-11-16 11:16:37,697 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:37,697 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:37,698 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:37,699 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:37,700 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 11:16:37,700 INFO L87 Difference]: Start difference. First operand 442 states and 572 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 11:16:38,094 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:38,094 INFO L93 Difference]: Finished difference Result 537 states and 697 transitions. [2022-11-16 11:16:38,095 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-11-16 11:16:38,096 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-11-16 11:16:38,096 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:38,100 INFO L225 Difference]: With dead ends: 537 [2022-11-16 11:16:38,100 INFO L226 Difference]: Without dead ends: 535 [2022-11-16 11:16:38,102 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-11-16 11:16:38,110 INFO L413 NwaCegarLoop]: 78 mSDtfsCounter, 144 mSDsluCounter, 238 mSDsCounter, 0 mSdLazyCounter, 259 mSolverCounterSat, 38 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 150 SdHoareTripleChecker+Valid, 316 SdHoareTripleChecker+Invalid, 297 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 38 IncrementalHoareTripleChecker+Valid, 259 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:38,113 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [150 Valid, 316 Invalid, 297 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [38 Valid, 259 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 11:16:38,114 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 535 states. [2022-11-16 11:16:38,171 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 535 to 506. [2022-11-16 11:16:38,173 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 506 states, 385 states have (on average 1.2727272727272727) internal successors, (490), 421 states have internal predecessors, (490), 61 states have call successors, (61), 51 states have call predecessors, (61), 59 states have return successors, (102), 53 states have call predecessors, (102), 61 states have call successors, (102) [2022-11-16 11:16:38,179 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 506 states to 506 states and 653 transitions. [2022-11-16 11:16:38,180 INFO L78 Accepts]: Start accepts. Automaton has 506 states and 653 transitions. Word has length 32 [2022-11-16 11:16:38,182 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:38,182 INFO L495 AbstractCegarLoop]: Abstraction has 506 states and 653 transitions. [2022-11-16 11:16:38,182 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 11:16:38,183 INFO L276 IsEmpty]: Start isEmpty. Operand 506 states and 653 transitions. [2022-11-16 11:16:38,188 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 11:16:38,189 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:38,189 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:38,189 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 11:16:38,190 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:38,190 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:38,190 INFO L85 PathProgramCache]: Analyzing trace with hash -1995340570, now seen corresponding path program 1 times [2022-11-16 11:16:38,191 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:38,192 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [426768073] [2022-11-16 11:16:38,192 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:38,194 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:38,219 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,314 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:38,321 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,328 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 11:16:38,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:38,374 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:38,421 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:38,422 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:38,422 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [426768073] [2022-11-16 11:16:38,423 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [426768073] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:38,423 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:38,423 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 11:16:38,423 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1437227824] [2022-11-16 11:16:38,424 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:38,424 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 11:16:38,425 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:38,426 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 11:16:38,426 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 11:16:38,426 INFO L87 Difference]: Start difference. First operand 506 states and 653 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:38,863 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:38,863 INFO L93 Difference]: Finished difference Result 1119 states and 1470 transitions. [2022-11-16 11:16:38,864 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-16 11:16:38,864 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2022-11-16 11:16:38,865 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:38,868 INFO L225 Difference]: With dead ends: 1119 [2022-11-16 11:16:38,869 INFO L226 Difference]: Without dead ends: 620 [2022-11-16 11:16:38,871 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-11-16 11:16:38,875 INFO L413 NwaCegarLoop]: 66 mSDtfsCounter, 147 mSDsluCounter, 248 mSDsCounter, 0 mSdLazyCounter, 318 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 147 SdHoareTripleChecker+Valid, 314 SdHoareTripleChecker+Invalid, 367 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 318 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:38,875 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [147 Valid, 314 Invalid, 367 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 318 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 11:16:38,878 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 620 states. [2022-11-16 11:16:38,955 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 620 to 566. [2022-11-16 11:16:38,956 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 566 states, 435 states have (on average 1.2551724137931035) internal successors, (546), 471 states have internal predecessors, (546), 61 states have call successors, (61), 51 states have call predecessors, (61), 69 states have return successors, (116), 61 states have call predecessors, (116), 61 states have call successors, (116) [2022-11-16 11:16:38,961 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 566 states to 566 states and 723 transitions. [2022-11-16 11:16:38,962 INFO L78 Accepts]: Start accepts. Automaton has 566 states and 723 transitions. Word has length 47 [2022-11-16 11:16:38,963 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:38,963 INFO L495 AbstractCegarLoop]: Abstraction has 566 states and 723 transitions. [2022-11-16 11:16:38,963 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:38,964 INFO L276 IsEmpty]: Start isEmpty. Operand 566 states and 723 transitions. [2022-11-16 11:16:38,965 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 11:16:38,965 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:38,965 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:38,966 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 11:16:38,966 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:38,966 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:38,967 INFO L85 PathProgramCache]: Analyzing trace with hash 1278558372, now seen corresponding path program 1 times [2022-11-16 11:16:38,967 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:38,967 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [962060150] [2022-11-16 11:16:38,967 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:38,968 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:39,008 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,167 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:39,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,181 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 11:16:39,185 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,205 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:39,208 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,284 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:39,284 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:39,284 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [962060150] [2022-11-16 11:16:39,285 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [962060150] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:39,285 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:39,285 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-16 11:16:39,291 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1939459013] [2022-11-16 11:16:39,292 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:39,292 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-16 11:16:39,292 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:39,293 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-16 11:16:39,294 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-11-16 11:16:39,294 INFO L87 Difference]: Start difference. First operand 566 states and 723 transitions. Second operand has 8 states, 8 states have (on average 5.0) internal successors, (40), 6 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:39,711 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:39,711 INFO L93 Difference]: Finished difference Result 1118 states and 1471 transitions. [2022-11-16 11:16:39,711 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-16 11:16:39,712 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.0) internal successors, (40), 6 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2022-11-16 11:16:39,712 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:39,715 INFO L225 Difference]: With dead ends: 1118 [2022-11-16 11:16:39,715 INFO L226 Difference]: Without dead ends: 559 [2022-11-16 11:16:39,717 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2022-11-16 11:16:39,718 INFO L413 NwaCegarLoop]: 63 mSDtfsCounter, 203 mSDsluCounter, 252 mSDsCounter, 0 mSdLazyCounter, 377 mSolverCounterSat, 69 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 203 SdHoareTripleChecker+Valid, 315 SdHoareTripleChecker+Invalid, 446 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 69 IncrementalHoareTripleChecker+Valid, 377 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:39,719 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [203 Valid, 315 Invalid, 446 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [69 Valid, 377 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 11:16:39,720 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 559 states. [2022-11-16 11:16:39,780 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 559 to 457. [2022-11-16 11:16:39,781 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 457 states, 350 states have (on average 1.2514285714285713) internal successors, (438), 379 states have internal predecessors, (438), 52 states have call successors, (52), 44 states have call predecessors, (52), 54 states have return successors, (88), 48 states have call predecessors, (88), 52 states have call successors, (88) [2022-11-16 11:16:39,783 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 457 states to 457 states and 578 transitions. [2022-11-16 11:16:39,784 INFO L78 Accepts]: Start accepts. Automaton has 457 states and 578 transitions. Word has length 47 [2022-11-16 11:16:39,784 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:39,784 INFO L495 AbstractCegarLoop]: Abstraction has 457 states and 578 transitions. [2022-11-16 11:16:39,784 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.0) internal successors, (40), 6 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:39,784 INFO L276 IsEmpty]: Start isEmpty. Operand 457 states and 578 transitions. [2022-11-16 11:16:39,785 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 11:16:39,786 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:39,786 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:39,786 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 11:16:39,786 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:39,787 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:39,787 INFO L85 PathProgramCache]: Analyzing trace with hash -715586334, now seen corresponding path program 1 times [2022-11-16 11:16:39,787 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:39,787 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [526570023] [2022-11-16 11:16:39,787 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:39,787 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:39,802 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,901 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:39,902 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,910 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 11:16:39,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,928 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:39,934 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:39,945 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:39,945 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:39,945 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [526570023] [2022-11-16 11:16:39,945 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [526570023] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:39,945 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 11:16:39,946 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 11:16:39,946 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1884406931] [2022-11-16 11:16:39,946 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:39,948 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 11:16:39,948 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:39,949 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 11:16:39,949 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 11:16:39,949 INFO L87 Difference]: Start difference. First operand 457 states and 578 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:40,568 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:40,568 INFO L93 Difference]: Finished difference Result 1035 states and 1392 transitions. [2022-11-16 11:16:40,569 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-16 11:16:40,569 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 47 [2022-11-16 11:16:40,576 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:40,581 INFO L225 Difference]: With dead ends: 1035 [2022-11-16 11:16:40,581 INFO L226 Difference]: Without dead ends: 702 [2022-11-16 11:16:40,583 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 58 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-11-16 11:16:40,586 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 219 mSDsluCounter, 326 mSDsCounter, 0 mSdLazyCounter, 438 mSolverCounterSat, 75 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 221 SdHoareTripleChecker+Valid, 418 SdHoareTripleChecker+Invalid, 513 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 75 IncrementalHoareTripleChecker+Valid, 438 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:40,587 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [221 Valid, 418 Invalid, 513 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [75 Valid, 438 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-16 11:16:40,588 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 702 states. [2022-11-16 11:16:40,674 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 702 to 677. [2022-11-16 11:16:40,675 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 677 states, 521 states have (on average 1.2284069097888675) internal successors, (640), 558 states have internal predecessors, (640), 76 states have call successors, (76), 66 states have call predecessors, (76), 79 states have return successors, (157), 78 states have call predecessors, (157), 76 states have call successors, (157) [2022-11-16 11:16:40,679 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 677 states to 677 states and 873 transitions. [2022-11-16 11:16:40,680 INFO L78 Accepts]: Start accepts. Automaton has 677 states and 873 transitions. Word has length 47 [2022-11-16 11:16:40,680 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:40,680 INFO L495 AbstractCegarLoop]: Abstraction has 677 states and 873 transitions. [2022-11-16 11:16:40,681 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 11:16:40,681 INFO L276 IsEmpty]: Start isEmpty. Operand 677 states and 873 transitions. [2022-11-16 11:16:40,686 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2022-11-16 11:16:40,686 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:40,686 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:40,687 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-16 11:16:40,687 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:40,687 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:40,688 INFO L85 PathProgramCache]: Analyzing trace with hash -1870420981, now seen corresponding path program 1 times [2022-11-16 11:16:40,688 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:40,688 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1559978841] [2022-11-16 11:16:40,688 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:40,689 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:40,720 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,904 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:40,905 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,918 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 11:16:40,921 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,941 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:40,944 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,953 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:40,955 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,965 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-11-16 11:16:40,968 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,973 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:40,974 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,975 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:40,976 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:40,978 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 11 proven. 9 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-16 11:16:40,978 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:40,978 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1559978841] [2022-11-16 11:16:40,978 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1559978841] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:40,978 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1487504752] [2022-11-16 11:16:40,978 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:40,979 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:40,979 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:40,982 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:41,004 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 11:16:41,154 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:41,158 INFO L263 TraceCheckSpWp]: Trace formula consists of 454 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-16 11:16:41,165 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:41,370 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 16 proven. 8 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 11:16:41,370 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 11:16:41,577 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 12 proven. 8 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-16 11:16:41,577 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1487504752] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 11:16:41,577 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 11:16:41,578 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-11-16 11:16:41,578 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1878947102] [2022-11-16 11:16:41,578 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 11:16:41,579 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-16 11:16:41,579 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:41,580 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-16 11:16:41,580 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-11-16 11:16:41,580 INFO L87 Difference]: Start difference. First operand 677 states and 873 transitions. Second operand has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2022-11-16 11:16:42,530 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:42,530 INFO L93 Difference]: Finished difference Result 1624 states and 2213 transitions. [2022-11-16 11:16:42,531 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-11-16 11:16:42,531 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) Word has length 89 [2022-11-16 11:16:42,533 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:42,540 INFO L225 Difference]: With dead ends: 1624 [2022-11-16 11:16:42,540 INFO L226 Difference]: Without dead ends: 1071 [2022-11-16 11:16:42,546 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 226 GetRequests, 190 SyntacticMatches, 9 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 204 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-11-16 11:16:42,547 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 280 mSDsluCounter, 462 mSDsCounter, 0 mSdLazyCounter, 689 mSolverCounterSat, 113 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 286 SdHoareTripleChecker+Valid, 557 SdHoareTripleChecker+Invalid, 802 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 113 IncrementalHoareTripleChecker+Valid, 689 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:42,549 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [286 Valid, 557 Invalid, 802 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [113 Valid, 689 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-16 11:16:42,550 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1071 states. [2022-11-16 11:16:42,661 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1071 to 936. [2022-11-16 11:16:42,663 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 936 states, 712 states have (on average 1.2359550561797752) internal successors, (880), 767 states have internal predecessors, (880), 111 states have call successors, (111), 95 states have call predecessors, (111), 112 states have return successors, (242), 105 states have call predecessors, (242), 111 states have call successors, (242) [2022-11-16 11:16:42,668 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 936 states to 936 states and 1233 transitions. [2022-11-16 11:16:42,669 INFO L78 Accepts]: Start accepts. Automaton has 936 states and 1233 transitions. Word has length 89 [2022-11-16 11:16:42,670 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:42,671 INFO L495 AbstractCegarLoop]: Abstraction has 936 states and 1233 transitions. [2022-11-16 11:16:42,671 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 9.777777777777779) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2022-11-16 11:16:42,671 INFO L276 IsEmpty]: Start isEmpty. Operand 936 states and 1233 transitions. [2022-11-16 11:16:42,681 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2022-11-16 11:16:42,682 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:42,682 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:42,689 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-16 11:16:42,888 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-16 11:16:42,889 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:42,889 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:42,889 INFO L85 PathProgramCache]: Analyzing trace with hash 309477364, now seen corresponding path program 2 times [2022-11-16 11:16:42,890 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:42,890 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [373440504] [2022-11-16 11:16:42,890 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:42,890 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:42,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,114 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:43,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,123 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 11:16:43,126 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,141 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:43,143 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,164 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:43,166 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,175 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-16 11:16:43,180 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,252 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 11:16:43,255 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:43,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:43,364 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,366 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-11-16 11:16:43,370 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,373 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:43,374 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,375 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:43,376 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:43,382 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 49 proven. 23 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-11-16 11:16:43,382 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:43,382 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [373440504] [2022-11-16 11:16:43,382 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [373440504] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:43,383 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1587115735] [2022-11-16 11:16:43,383 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-11-16 11:16:43,383 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:43,383 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:43,387 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:43,406 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 11:16:43,530 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-11-16 11:16:43,530 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-11-16 11:16:43,533 INFO L263 TraceCheckSpWp]: Trace formula consists of 562 conjuncts, 10 conjunts are in the unsatisfiable core [2022-11-16 11:16:43,537 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:43,639 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 76 proven. 0 refuted. 0 times theorem prover too weak. 14 trivial. 0 not checked. [2022-11-16 11:16:43,640 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 11:16:43,640 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1587115735] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:43,640 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 11:16:43,640 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 12 [2022-11-16 11:16:43,641 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [549083315] [2022-11-16 11:16:43,641 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:43,641 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 11:16:43,641 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:43,642 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 11:16:43,642 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2022-11-16 11:16:43,643 INFO L87 Difference]: Start difference. First operand 936 states and 1233 transitions. Second operand has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2022-11-16 11:16:44,114 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:44,114 INFO L93 Difference]: Finished difference Result 2509 states and 3457 transitions. [2022-11-16 11:16:44,114 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-16 11:16:44,115 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) Word has length 131 [2022-11-16 11:16:44,115 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:44,123 INFO L225 Difference]: With dead ends: 2509 [2022-11-16 11:16:44,123 INFO L226 Difference]: Without dead ends: 1695 [2022-11-16 11:16:44,127 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 171 GetRequests, 153 SyntacticMatches, 3 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 31 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=57, Invalid=215, Unknown=0, NotChecked=0, Total=272 [2022-11-16 11:16:44,128 INFO L413 NwaCegarLoop]: 188 mSDtfsCounter, 234 mSDsluCounter, 434 mSDsCounter, 0 mSdLazyCounter, 157 mSolverCounterSat, 47 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 234 SdHoareTripleChecker+Valid, 622 SdHoareTripleChecker+Invalid, 204 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 47 IncrementalHoareTripleChecker+Valid, 157 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:44,128 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [234 Valid, 622 Invalid, 204 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [47 Valid, 157 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 11:16:44,131 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1695 states. [2022-11-16 11:16:44,287 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1695 to 1659. [2022-11-16 11:16:44,290 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1659 states, 1262 states have (on average 1.2345483359746434) internal successors, (1558), 1344 states have internal predecessors, (1558), 192 states have call successors, (192), 170 states have call predecessors, (192), 204 states have return successors, (394), 194 states have call predecessors, (394), 192 states have call successors, (394) [2022-11-16 11:16:44,303 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1659 states to 1659 states and 2144 transitions. [2022-11-16 11:16:44,303 INFO L78 Accepts]: Start accepts. Automaton has 1659 states and 2144 transitions. Word has length 131 [2022-11-16 11:16:44,304 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:44,304 INFO L495 AbstractCegarLoop]: Abstraction has 1659 states and 2144 transitions. [2022-11-16 11:16:44,304 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 16.5) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2022-11-16 11:16:44,305 INFO L276 IsEmpty]: Start isEmpty. Operand 1659 states and 2144 transitions. [2022-11-16 11:16:44,311 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 132 [2022-11-16 11:16:44,311 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 11:16:44,311 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:44,324 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 11:16:44,517 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-16 11:16:44,518 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 11:16:44,518 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 11:16:44,518 INFO L85 PathProgramCache]: Analyzing trace with hash -107919242, now seen corresponding path program 1 times [2022-11-16 11:16:44,518 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 11:16:44,519 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2034246485] [2022-11-16 11:16:44,519 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:44,519 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 11:16:44,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,692 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 11:16:44,693 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,703 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 11:16:44,705 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,715 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 11:16:44,717 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,720 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2022-11-16 11:16:44,729 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,754 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 11:16:44,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:44,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,804 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-11-16 11:16:44,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,809 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-11-16 11:16:44,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,812 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 11:16:44,813 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,814 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 41 trivial. 0 not checked. [2022-11-16 11:16:44,815 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 11:16:44,815 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2034246485] [2022-11-16 11:16:44,815 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2034246485] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 11:16:44,815 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1808980904] [2022-11-16 11:16:44,816 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 11:16:44,816 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 11:16:44,816 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 11:16:44,817 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 11:16:44,829 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 11:16:44,971 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 11:16:44,973 INFO L263 TraceCheckSpWp]: Trace formula consists of 563 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-16 11:16:44,977 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 11:16:45,010 INFO L134 CoverageAnalysis]: Checked inductivity of 90 backedges. 62 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-11-16 11:16:45,010 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 11:16:45,011 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1808980904] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 11:16:45,011 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 11:16:45,011 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [10] total 12 [2022-11-16 11:16:45,011 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [477953320] [2022-11-16 11:16:45,011 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 11:16:45,012 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 11:16:45,012 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 11:16:45,012 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 11:16:45,013 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=25, Invalid=107, Unknown=0, NotChecked=0, Total=132 [2022-11-16 11:16:45,013 INFO L87 Difference]: Start difference. First operand 1659 states and 2144 transitions. Second operand has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 11:16:45,111 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 11:16:45,111 INFO L93 Difference]: Finished difference Result 2287 states and 2930 transitions. [2022-11-16 11:16:45,111 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 11:16:45,112 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 131 [2022-11-16 11:16:45,112 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 11:16:45,113 INFO L225 Difference]: With dead ends: 2287 [2022-11-16 11:16:45,113 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 11:16:45,118 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 165 GetRequests, 153 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=38, Invalid=144, Unknown=0, NotChecked=0, Total=182 [2022-11-16 11:16:45,119 INFO L413 NwaCegarLoop]: 104 mSDtfsCounter, 9 mSDsluCounter, 295 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 399 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 11:16:45,120 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 399 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 11:16:45,120 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 11:16:45,121 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 11:16:45,121 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 11:16:45,121 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 11:16:45,121 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 131 [2022-11-16 11:16:45,122 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 11:16:45,122 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 11:16:45,122 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.2) internal successors, (91), 5 states have internal predecessors, (91), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 11:16:45,122 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 11:16:45,122 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 11:16:45,125 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 11:16:45,137 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 11:16:45,332 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-16 11:16:45,335 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 11:16:49,486 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 252 259) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,486 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 252 259) no Hoare annotation was computed. [2022-11-16 11:16:49,486 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 252 259) no Hoare annotation was computed. [2022-11-16 11:16:49,486 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 159 165) no Hoare annotation was computed. [2022-11-16 11:16:49,486 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 159 165) the Hoare annotation is: true [2022-11-16 11:16:49,486 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 933 944) the Hoare annotation is: true [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point L937-1(lines 933 944) no Hoare annotation was computed. [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 933 944) no Hoare annotation was computed. [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 446 475) no Hoare annotation was computed. [2022-11-16 11:16:49,487 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 446 475) the Hoare annotation is: true [2022-11-16 11:16:49,487 INFO L902 garLoopResultBuilder]: At program point L471(lines 446 475) the Hoare annotation is: true [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point L467(line 467) no Hoare annotation was computed. [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point L460(lines 460 464) no Hoare annotation was computed. [2022-11-16 11:16:49,487 INFO L902 garLoopResultBuilder]: At program point L460-1(lines 460 464) the Hoare annotation is: true [2022-11-16 11:16:49,487 INFO L899 garLoopResultBuilder]: For program point L457(line 457) no Hoare annotation was computed. [2022-11-16 11:16:49,488 INFO L902 garLoopResultBuilder]: At program point L456-2(lines 456 470) the Hoare annotation is: true [2022-11-16 11:16:49,488 INFO L902 garLoopResultBuilder]: At program point L452(line 452) the Hoare annotation is: true [2022-11-16 11:16:49,488 INFO L899 garLoopResultBuilder]: For program point L452-1(line 452) no Hoare annotation was computed. [2022-11-16 11:16:49,488 INFO L899 garLoopResultBuilder]: For program point L440(line 440) no Hoare annotation was computed. [2022-11-16 11:16:49,488 INFO L895 garLoopResultBuilder]: At program point L238(line 238) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-11-16 11:16:49,488 INFO L895 garLoopResultBuilder]: At program point L238-1(lines 219 243) the Hoare annotation is: (let ((.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0)) (.cse0 (= ~pumpRunning~0 0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or .cse3 .cse4 (and .cse0 (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 11:16:49,489 INFO L895 garLoopResultBuilder]: At program point L267(lines 260 270) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,489 INFO L899 garLoopResultBuilder]: For program point L139-1(lines 138 157) no Hoare annotation was computed. [2022-11-16 11:16:49,489 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 135 158) no Hoare annotation was computed. [2022-11-16 11:16:49,489 INFO L895 garLoopResultBuilder]: At program point L441(lines 436 443) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,489 INFO L895 garLoopResultBuilder]: At program point L982(lines 977 985) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse7 .cse6 .cse8 (not .cse2))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3) (or .cse0 (and .cse5 .cse6) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (and .cse7 .cse8) (and .cse5 (<= 1 ~waterLevel~0) .cse4) .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-16 11:16:49,490 INFO L895 garLoopResultBuilder]: At program point L276(lines 271 279) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,490 INFO L899 garLoopResultBuilder]: For program point L227(lines 227 235) no Hoare annotation was computed. [2022-11-16 11:16:49,490 INFO L899 garLoopResultBuilder]: For program point L384(lines 384 390) no Hoare annotation was computed. [2022-11-16 11:16:49,490 INFO L899 garLoopResultBuilder]: For program point L223(lines 223 240) no Hoare annotation was computed. [2022-11-16 11:16:49,490 INFO L899 garLoopResultBuilder]: For program point L380(lines 380 393) no Hoare annotation was computed. [2022-11-16 11:16:49,490 INFO L895 garLoopResultBuilder]: At program point L380-1(lines 372 396) the Hoare annotation is: (let ((.cse4 (<= 2 ~waterLevel~0)) (.cse5 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse1 (= 0 ~systemActive~0))) (let ((.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (= ~pumpRunning~0 0)) (.cse8 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|)) (.cse9 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse2 (and .cse4 .cse5 .cse10 .cse6 (not .cse1)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 .cse1 .cse2 .cse3) (or (and .cse4 .cse5 .cse6) (and .cse7 .cse8 (<= 1 ~waterLevel~0) .cse9) .cse1 .cse3) (or .cse0 (not (<= 1 |old(~waterLevel~0)|)) (and .cse7 .cse8 .cse9 .cse10) .cse2)))) [2022-11-16 11:16:49,491 INFO L895 garLoopResultBuilder]: At program point L950(lines 945 953) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,491 INFO L899 garLoopResultBuilder]: For program point L913(lines 913 917) no Hoare annotation was computed. [2022-11-16 11:16:49,491 INFO L895 garLoopResultBuilder]: At program point L913-2(lines 909 920) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,491 INFO L899 garLoopResultBuilder]: For program point L146-1(lines 146 152) no Hoare annotation was computed. [2022-11-16 11:16:49,491 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 135 158) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 11:16:49,491 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 135 158) no Hoare annotation was computed. [2022-11-16 11:16:49,491 INFO L895 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,492 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 440) no Hoare annotation was computed. [2022-11-16 11:16:49,492 INFO L895 garLoopResultBuilder]: At program point L229(line 229) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-11-16 11:16:49,492 INFO L899 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2022-11-16 11:16:49,492 INFO L899 garLoopResultBuilder]: For program point L85-1(lines 85 91) no Hoare annotation was computed. [2022-11-16 11:16:49,492 INFO L899 garLoopResultBuilder]: For program point L527(lines 527 534) no Hoare annotation was computed. [2022-11-16 11:16:49,492 INFO L895 garLoopResultBuilder]: At program point L366(lines 354 368) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1)))) [2022-11-16 11:16:49,492 INFO L895 garLoopResultBuilder]: At program point L110(lines 65 112) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-11-16 11:16:49,493 INFO L895 garLoopResultBuilder]: At program point L77(line 77) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point L527-2(lines 527 534) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point L358(lines 358 364) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point L358-1(lines 358 364) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L895 garLoopResultBuilder]: At program point L416(lines 412 418) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 11:16:49,493 INFO L902 garLoopResultBuilder]: At program point L536(lines 517 539) the Hoare annotation is: true [2022-11-16 11:16:49,494 INFO L899 garLoopResultBuilder]: For program point L66(lines 65 112) no Hoare annotation was computed. [2022-11-16 11:16:49,494 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 11:16:49,494 INFO L899 garLoopResultBuilder]: For program point L95(lines 95 108) no Hoare annotation was computed. [2022-11-16 11:16:49,494 INFO L895 garLoopResultBuilder]: At program point L504(lines 500 506) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0)) [2022-11-16 11:16:49,494 INFO L895 garLoopResultBuilder]: At program point L87(line 87) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-11-16 11:16:49,496 INFO L902 garLoopResultBuilder]: At program point L116(lines 55 120) the Hoare annotation is: true [2022-11-16 11:16:49,496 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 81) no Hoare annotation was computed. [2022-11-16 11:16:49,496 INFO L899 garLoopResultBuilder]: For program point L75-1(lines 75 81) no Hoare annotation was computed. [2022-11-16 11:16:49,496 INFO L895 garLoopResultBuilder]: At program point L360(line 360) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~7#1| 1) (= |ULTIMATE.start_valid_product_#res#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-11-16 11:16:49,496 INFO L899 garLoopResultBuilder]: For program point L67(lines 67 71) no Hoare annotation was computed. [2022-11-16 11:16:49,497 INFO L895 garLoopResultBuilder]: At program point L113(lines 64 114) the Hoare annotation is: false [2022-11-16 11:16:49,497 INFO L895 garLoopResultBuilder]: At program point L431(lines 426 434) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:49,497 INFO L895 garLoopResultBuilder]: At program point L423(lines 419 425) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 11:16:49,497 INFO L899 garLoopResultBuilder]: For program point L101(lines 101 107) no Hoare annotation was computed. [2022-11-16 11:16:49,498 INFO L895 garLoopResultBuilder]: At program point L101-2(lines 95 108) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-11-16 11:16:49,498 INFO L902 garLoopResultBuilder]: At program point L514(lines 507 516) the Hoare annotation is: true [2022-11-16 11:16:49,498 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 167 191) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,498 INFO L895 garLoopResultBuilder]: At program point L186(line 186) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,498 INFO L899 garLoopResultBuilder]: For program point L186-1(lines 167 191) no Hoare annotation was computed. [2022-11-16 11:16:49,499 INFO L895 garLoopResultBuilder]: At program point L331(lines 316 334) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse1) (let ((.cse2 (= ~pumpRunning~0 0))) (or .cse0 (not (<= 1 ~waterLevel~0)) (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (and .cse2 (<= 2 ~waterLevel~0)) .cse1)))) [2022-11-16 11:16:49,499 INFO L899 garLoopResultBuilder]: For program point L325(lines 325 329) no Hoare annotation was computed. [2022-11-16 11:16:49,499 INFO L899 garLoopResultBuilder]: For program point L325-2(lines 325 329) no Hoare annotation was computed. [2022-11-16 11:16:49,499 INFO L899 garLoopResultBuilder]: For program point L990(lines 990 996) no Hoare annotation was computed. [2022-11-16 11:16:49,499 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 167 191) no Hoare annotation was computed. [2022-11-16 11:16:49,499 INFO L895 garLoopResultBuilder]: At program point L249(lines 244 251) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,500 INFO L895 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1| 0))) .cse1))) [2022-11-16 11:16:49,500 INFO L899 garLoopResultBuilder]: For program point L175(lines 175 183) no Hoare annotation was computed. [2022-11-16 11:16:49,500 INFO L899 garLoopResultBuilder]: For program point L171(lines 171 188) no Hoare annotation was computed. [2022-11-16 11:16:49,500 INFO L895 garLoopResultBuilder]: At program point L995(lines 986 999) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-11-16 11:16:49,500 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 921 932) no Hoare annotation was computed. [2022-11-16 11:16:49,501 INFO L899 garLoopResultBuilder]: For program point L925-1(lines 921 932) no Hoare annotation was computed. [2022-11-16 11:16:49,501 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 921 932) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 11:16:49,501 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 193 217) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,501 INFO L895 garLoopResultBuilder]: At program point L207(line 207) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,502 INFO L895 garLoopResultBuilder]: At program point L203(line 203) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0))))) [2022-11-16 11:16:49,502 INFO L899 garLoopResultBuilder]: For program point L201(lines 201 209) no Hoare annotation was computed. [2022-11-16 11:16:49,502 INFO L899 garLoopResultBuilder]: For program point L197(lines 197 214) no Hoare annotation was computed. [2022-11-16 11:16:49,502 INFO L895 garLoopResultBuilder]: At program point L350(lines 335 353) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or (and (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 11:16:49,502 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 193 217) no Hoare annotation was computed. [2022-11-16 11:16:49,502 INFO L899 garLoopResultBuilder]: For program point L344(lines 344 348) no Hoare annotation was computed. [2022-11-16 11:16:49,503 INFO L899 garLoopResultBuilder]: For program point L344-2(lines 344 348) no Hoare annotation was computed. [2022-11-16 11:16:49,503 INFO L895 garLoopResultBuilder]: At program point L212(line 212) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0)) (= 0 ~systemActive~0)) [2022-11-16 11:16:49,503 INFO L899 garLoopResultBuilder]: For program point L212-1(lines 193 217) no Hoare annotation was computed. [2022-11-16 11:16:49,503 INFO L895 garLoopResultBuilder]: At program point L1005(lines 1000 1008) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-16 11:16:49,507 INFO L444 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 11:16:49,509 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 11:16:49,531 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 11:16:49 BoogieIcfgContainer [2022-11-16 11:16:49,531 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 11:16:49,532 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 11:16:49,532 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 11:16:49,532 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 11:16:49,533 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 11:16:34" (3/4) ... [2022-11-16 11:16:49,535 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 11:16:49,542 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-16 11:16:49,542 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 11:16:49,542 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 11:16:49,542 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 11:16:49,542 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 11:16:49,543 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 11:16:49,543 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 11:16:49,543 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-11-16 11:16:49,551 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-16 11:16:49,551 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 11:16:49,552 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 11:16:49,552 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 11:16:49,553 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 11:16:49,553 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 11:16:49,553 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 11:16:49,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-11-16 11:16:49,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive [2022-11-16 11:16:49,579 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1)) || ((((tmp == 1 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) [2022-11-16 11:16:49,579 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,580 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-11-16 11:16:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1) [2022-11-16 11:16:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1)) && (((!(\old(pumpRunning) == 0) || 0 == systemActive) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(2 <= \old(waterLevel)))) && (((((2 <= waterLevel && 2 <= tmp) && 2 <= \result) || (((pumpRunning == 0 && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || (((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) [2022-11-16 11:16:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-11-16 11:16:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,583 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive [2022-11-16 11:16:49,583 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((tmp == 0 && pumpRunning == \old(pumpRunning)) && 1 <= \result) && 1 <= tmp___0) && \result == 0) || !(1 <= waterLevel)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-11-16 11:16:49,583 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-11-16 11:16:49,583 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\result == 0)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (((pumpRunning == 0 && tmp___0 == 0) && !(tmp == 0)) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive) [2022-11-16 11:16:49,584 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-11-16 11:16:49,630 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 11:16:49,631 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 11:16:49,631 INFO L158 Benchmark]: Toolchain (without parser) took 16441.96ms. Allocated memory was 98.6MB in the beginning and 222.3MB in the end (delta: 123.7MB). Free memory was 61.5MB in the beginning and 180.7MB in the end (delta: -119.1MB). Peak memory consumption was 4.0MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,632 INFO L158 Benchmark]: CDTParser took 0.27ms. Allocated memory is still 98.6MB. Free memory was 79.2MB in the beginning and 79.2MB in the end (delta: 77.2kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 11:16:49,632 INFO L158 Benchmark]: CACSL2BoogieTranslator took 751.08ms. Allocated memory is still 98.6MB. Free memory was 61.3MB in the beginning and 66.7MB in the end (delta: -5.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,632 INFO L158 Benchmark]: Boogie Procedure Inliner took 93.77ms. Allocated memory is still 98.6MB. Free memory was 66.7MB in the beginning and 64.0MB in the end (delta: 2.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,633 INFO L158 Benchmark]: Boogie Preprocessor took 33.91ms. Allocated memory is still 98.6MB. Free memory was 64.0MB in the beginning and 62.4MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 11:16:49,633 INFO L158 Benchmark]: RCFGBuilder took 784.03ms. Allocated memory is still 98.6MB. Free memory was 62.1MB in the beginning and 42.7MB in the end (delta: 19.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,634 INFO L158 Benchmark]: TraceAbstraction took 14664.95ms. Allocated memory was 98.6MB in the beginning and 222.3MB in the end (delta: 123.7MB). Free memory was 41.9MB in the beginning and 187.0MB in the end (delta: -145.1MB). Peak memory consumption was 111.4MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,634 INFO L158 Benchmark]: Witness Printer took 99.15ms. Allocated memory is still 222.3MB. Free memory was 187.0MB in the beginning and 180.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 11:16:49,636 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.27ms. Allocated memory is still 98.6MB. Free memory was 79.2MB in the beginning and 79.2MB in the end (delta: 77.2kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 751.08ms. Allocated memory is still 98.6MB. Free memory was 61.3MB in the beginning and 66.7MB in the end (delta: -5.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 93.77ms. Allocated memory is still 98.6MB. Free memory was 66.7MB in the beginning and 64.0MB in the end (delta: 2.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 33.91ms. Allocated memory is still 98.6MB. Free memory was 64.0MB in the beginning and 62.4MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 784.03ms. Allocated memory is still 98.6MB. Free memory was 62.1MB in the beginning and 42.7MB in the end (delta: 19.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 14664.95ms. Allocated memory was 98.6MB in the beginning and 222.3MB in the end (delta: 123.7MB). Free memory was 41.9MB in the beginning and 187.0MB in the end (delta: -145.1MB). Peak memory consumption was 111.4MB. Max. memory is 16.1GB. * Witness Printer took 99.15ms. Allocated memory is still 222.3MB. Free memory was 187.0MB in the beginning and 180.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 440]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 99 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 14.5s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 4.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.2s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1624 SdHoareTripleChecker+Valid, 2.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1606 mSDsluCounter, 4388 SdHoareTripleChecker+Invalid, 1.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3113 mSDsCounter, 422 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2408 IncrementalHoareTripleChecker+Invalid, 2830 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 422 mSolverCounterUnsat, 1275 mSDtfsCounter, 2408 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 666 GetRequests, 537 SyntacticMatches, 14 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 329 ImplicationChecksByTransitivity, 1.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1659occurred in iteration=11, InterpolantAutomatonStates: 108, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.9s AutomataMinimizationTime, 12 MinimizatonAttempts, 398 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 47 LocationsWithAnnotation, 2851 PreInvPairs, 3108 NumberOfFragments, 1159 HoareAnnotationTreeSize, 2851 FomulaSimplifications, 3646 FormulaSimplificationTreeSizeReduction, 0.7s HoareSimplificationTime, 47 FomulaSimplificationsInter, 14061 FormulaSimplificationTreeSizeReductionInter, 3.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 3.1s InterpolantComputationTime, 996 NumberOfCodeBlocks, 996 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 1069 ConstructedInterpolants, 0 QuantifiedInterpolants, 1909 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1579 ConjunctsInSsa, 23 ConjunctsInUnsatCore, 16 InterpolantComputations, 11 PerfectInterpolantSequences, 378/432 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 1000]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 456]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 65]: Loop Invariant Derived loop invariant: (((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1)) || ((((tmp == 1 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 446]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 986]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive - InvariantResult [Line: 372]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1)) && (((!(\old(pumpRunning) == 0) || 0 == systemActive) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(2 <= \old(waterLevel)))) && (((((2 <= waterLevel && 2 <= tmp) && 2 <= \result) || (((pumpRunning == 0 && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || (((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) - InvariantResult [Line: 354]: Loop Invariant Derived loop invariant: ((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 500]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\result == 0)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (((pumpRunning == 0 && tmp___0 == 0) && !(tmp == 0)) && \result == 0)) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 507]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 436]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 945]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 335]: Loop Invariant Derived loop invariant: ((((((tmp == 0 && pumpRunning == \old(pumpRunning)) && 1 <= \result) && 1 <= tmp___0) && \result == 0) || !(1 <= waterLevel)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 412]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 271]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 260]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 909]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 244]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 426]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 55]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 219]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 517]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-16 11:16:49,697 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_45a3a45e-ace3-49fa-9aa7-e2cdc2ad2453/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE