./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 10:55:03,356 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 10:55:03,359 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 10:55:03,403 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 10:55:03,405 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 10:55:03,409 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 10:55:03,412 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 10:55:03,416 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 10:55:03,418 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 10:55:03,421 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 10:55:03,423 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 10:55:03,425 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 10:55:03,426 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 10:55:03,431 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 10:55:03,432 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 10:55:03,434 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 10:55:03,436 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 10:55:03,437 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 10:55:03,438 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 10:55:03,446 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 10:55:03,448 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 10:55:03,452 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 10:55:03,455 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 10:55:03,456 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 10:55:03,465 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 10:55:03,467 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 10:55:03,468 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 10:55:03,469 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 10:55:03,471 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 10:55:03,472 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 10:55:03,472 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 10:55:03,473 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 10:55:03,475 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 10:55:03,476 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 10:55:03,477 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 10:55:03,478 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 10:55:03,478 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 10:55:03,479 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 10:55:03,479 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 10:55:03,480 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 10:55:03,481 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 10:55:03,482 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 10:55:03,525 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 10:55:03,526 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 10:55:03,527 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 10:55:03,527 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 10:55:03,528 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 10:55:03,528 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 10:55:03,529 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 10:55:03,529 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 10:55:03,529 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 10:55:03,530 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 10:55:03,531 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 10:55:03,531 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 10:55:03,531 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 10:55:03,531 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 10:55:03,532 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 10:55:03,532 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 10:55:03,532 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 10:55:03,532 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 10:55:03,532 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 10:55:03,533 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 10:55:03,533 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 10:55:03,533 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 10:55:03,533 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 10:55:03,534 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 10:55:03,534 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 10:55:03,534 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 10:55:03,536 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 10:55:03,536 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 10:55:03,536 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 10:55:03,536 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 10:55:03,536 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 10:55:03,537 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 10:55:03,537 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 10:55:03,537 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d [2022-11-16 10:55:03,883 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 10:55:03,916 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 10:55:03,938 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 10:55:03,940 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 10:55:03,943 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 10:55:03,947 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2022-11-16 10:55:04,026 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/data/2354b8181/5520928e89fa4216874e888bb52750ec/FLAG443a43bcb [2022-11-16 10:55:04,674 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 10:55:04,675 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2022-11-16 10:55:04,689 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/data/2354b8181/5520928e89fa4216874e888bb52750ec/FLAG443a43bcb [2022-11-16 10:55:04,991 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/data/2354b8181/5520928e89fa4216874e888bb52750ec [2022-11-16 10:55:04,994 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 10:55:04,996 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 10:55:05,002 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 10:55:05,002 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 10:55:05,007 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 10:55:05,008 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 10:55:04" (1/1) ... [2022-11-16 10:55:05,010 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7382e78b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05, skipping insertion in model container [2022-11-16 10:55:05,011 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 10:55:04" (1/1) ... [2022-11-16 10:55:05,020 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 10:55:05,093 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 10:55:05,399 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2022-11-16 10:55:05,460 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 10:55:05,471 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 10:55:05,548 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2022-11-16 10:55:05,603 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 10:55:05,637 INFO L208 MainTranslator]: Completed translation [2022-11-16 10:55:05,638 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05 WrapperNode [2022-11-16 10:55:05,639 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 10:55:05,640 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 10:55:05,641 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 10:55:05,641 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 10:55:05,650 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,685 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,723 INFO L138 Inliner]: procedures = 57, calls = 157, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 283 [2022-11-16 10:55:05,724 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 10:55:05,725 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 10:55:05,725 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 10:55:05,725 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 10:55:05,734 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,734 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,737 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,737 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,743 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,749 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,751 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,752 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,755 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 10:55:05,756 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 10:55:05,757 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 10:55:05,757 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 10:55:05,758 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (1/1) ... [2022-11-16 10:55:05,766 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 10:55:05,780 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:55:05,792 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 10:55:05,819 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 10:55:05,842 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 10:55:05,843 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 10:55:05,843 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 10:55:05,843 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 10:55:05,843 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 10:55:05,844 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 10:55:05,844 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 10:55:05,844 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:55:05,844 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:55:05,844 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 10:55:05,845 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 10:55:05,845 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 10:55:05,845 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 10:55:05,845 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 10:55:05,846 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 10:55:05,846 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 10:55:05,953 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 10:55:05,956 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 10:55:06,533 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 10:55:06,543 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 10:55:06,549 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 10:55:06,553 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:55:06 BoogieIcfgContainer [2022-11-16 10:55:06,553 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 10:55:06,556 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 10:55:06,556 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 10:55:06,563 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 10:55:06,563 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 10:55:04" (1/3) ... [2022-11-16 10:55:06,564 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7fa5e5fe and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 10:55:06, skipping insertion in model container [2022-11-16 10:55:06,564 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 10:55:05" (2/3) ... [2022-11-16 10:55:06,565 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7fa5e5fe and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 10:55:06, skipping insertion in model container [2022-11-16 10:55:06,565 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:55:06" (3/3) ... [2022-11-16 10:55:06,567 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product58.cil.c [2022-11-16 10:55:06,597 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 10:55:06,598 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 10:55:06,679 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 10:55:06,688 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@49c95d90, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 10:55:06,688 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 10:55:06,693 INFO L276 IsEmpty]: Start isEmpty. Operand has 87 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2022-11-16 10:55:06,705 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-16 10:55:06,705 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:06,706 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:06,707 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:06,713 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:06,714 INFO L85 PathProgramCache]: Analyzing trace with hash -644164364, now seen corresponding path program 1 times [2022-11-16 10:55:06,725 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:06,726 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1001721358] [2022-11-16 10:55:06,726 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:06,727 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:06,994 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:07,130 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:07,131 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:07,131 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1001721358] [2022-11-16 10:55:07,132 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1001721358] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:07,132 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:07,133 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 10:55:07,134 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [596182409] [2022-11-16 10:55:07,136 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:07,141 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 10:55:07,142 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:07,176 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 10:55:07,177 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 10:55:07,180 INFO L87 Difference]: Start difference. First operand has 87 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,262 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:07,264 INFO L93 Difference]: Finished difference Result 166 states and 227 transitions. [2022-11-16 10:55:07,266 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 10:55:07,268 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-16 10:55:07,269 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:07,310 INFO L225 Difference]: With dead ends: 166 [2022-11-16 10:55:07,311 INFO L226 Difference]: Without dead ends: 78 [2022-11-16 10:55:07,317 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 10:55:07,326 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 110 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:07,327 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 110 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:55:07,352 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2022-11-16 10:55:07,403 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2022-11-16 10:55:07,406 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 62 states have (on average 1.3225806451612903) internal successors, (82), 69 states have internal predecessors, (82), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-16 10:55:07,415 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 101 transitions. [2022-11-16 10:55:07,417 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 101 transitions. Word has length 19 [2022-11-16 10:55:07,418 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:07,418 INFO L495 AbstractCegarLoop]: Abstraction has 78 states and 101 transitions. [2022-11-16 10:55:07,418 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,419 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 101 transitions. [2022-11-16 10:55:07,427 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-16 10:55:07,428 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:07,428 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:07,429 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 10:55:07,429 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:07,433 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:07,433 INFO L85 PathProgramCache]: Analyzing trace with hash -1321297108, now seen corresponding path program 1 times [2022-11-16 10:55:07,433 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:07,434 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [91353295] [2022-11-16 10:55:07,434 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:07,434 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:07,473 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:07,591 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:07,592 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:07,592 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [91353295] [2022-11-16 10:55:07,592 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [91353295] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:07,593 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:07,593 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 10:55:07,593 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [742360189] [2022-11-16 10:55:07,593 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:07,595 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 10:55:07,595 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:07,596 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 10:55:07,596 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:55:07,596 INFO L87 Difference]: Start difference. First operand 78 states and 101 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,618 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:07,618 INFO L93 Difference]: Finished difference Result 121 states and 157 transitions. [2022-11-16 10:55:07,619 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 10:55:07,619 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-16 10:55:07,620 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:07,621 INFO L225 Difference]: With dead ends: 121 [2022-11-16 10:55:07,621 INFO L226 Difference]: Without dead ends: 69 [2022-11-16 10:55:07,622 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:55:07,624 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 13 mSDsluCounter, 71 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 159 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:07,625 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 159 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:55:07,626 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2022-11-16 10:55:07,635 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2022-11-16 10:55:07,635 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 56 states have (on average 1.3392857142857142) internal successors, (75), 63 states have internal predecessors, (75), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-16 10:55:07,636 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 89 transitions. [2022-11-16 10:55:07,637 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 89 transitions. Word has length 20 [2022-11-16 10:55:07,637 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:07,637 INFO L495 AbstractCegarLoop]: Abstraction has 69 states and 89 transitions. [2022-11-16 10:55:07,638 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,638 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 89 transitions. [2022-11-16 10:55:07,639 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-16 10:55:07,639 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:07,639 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:07,640 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 10:55:07,640 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:07,641 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:07,641 INFO L85 PathProgramCache]: Analyzing trace with hash 2055869510, now seen corresponding path program 1 times [2022-11-16 10:55:07,641 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:07,642 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [114975992] [2022-11-16 10:55:07,642 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:07,642 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:07,672 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:07,766 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:07,767 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:07,767 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [114975992] [2022-11-16 10:55:07,767 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [114975992] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:07,767 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:07,768 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 10:55:07,768 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1095712148] [2022-11-16 10:55:07,768 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:07,769 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 10:55:07,769 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:07,769 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 10:55:07,770 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:55:07,770 INFO L87 Difference]: Start difference. First operand 69 states and 89 transitions. Second operand has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,791 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:07,792 INFO L93 Difference]: Finished difference Result 131 states and 172 transitions. [2022-11-16 10:55:07,792 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 10:55:07,793 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-11-16 10:55:07,793 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:07,794 INFO L225 Difference]: With dead ends: 131 [2022-11-16 10:55:07,795 INFO L226 Difference]: Without dead ends: 69 [2022-11-16 10:55:07,796 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 10:55:07,797 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 69 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 87 SdHoareTripleChecker+Invalid, 2 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:07,798 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 87 Invalid, 2 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 10:55:07,799 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2022-11-16 10:55:07,808 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2022-11-16 10:55:07,809 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 56 states have (on average 1.3214285714285714) internal successors, (74), 63 states have internal predecessors, (74), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-16 10:55:07,810 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 88 transitions. [2022-11-16 10:55:07,811 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 88 transitions. Word has length 25 [2022-11-16 10:55:07,811 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:07,811 INFO L495 AbstractCegarLoop]: Abstraction has 69 states and 88 transitions. [2022-11-16 10:55:07,812 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:07,812 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 88 transitions. [2022-11-16 10:55:07,813 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-16 10:55:07,814 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:07,814 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:07,814 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 10:55:07,814 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:07,815 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:07,815 INFO L85 PathProgramCache]: Analyzing trace with hash 86695610, now seen corresponding path program 1 times [2022-11-16 10:55:07,816 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:07,816 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1112304335] [2022-11-16 10:55:07,816 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:07,816 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:07,842 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,004 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:08,007 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,045 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:08,049 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,059 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:08,061 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:08,062 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1112304335] [2022-11-16 10:55:08,062 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1112304335] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:08,064 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:08,065 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 10:55:08,065 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [822166719] [2022-11-16 10:55:08,066 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:08,068 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 10:55:08,070 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:08,070 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 10:55:08,072 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 10:55:08,073 INFO L87 Difference]: Start difference. First operand 69 states and 88 transitions. Second operand has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:08,351 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:08,351 INFO L93 Difference]: Finished difference Result 195 states and 249 transitions. [2022-11-16 10:55:08,352 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 10:55:08,352 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 35 [2022-11-16 10:55:08,353 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:08,354 INFO L225 Difference]: With dead ends: 195 [2022-11-16 10:55:08,354 INFO L226 Difference]: Without dead ends: 133 [2022-11-16 10:55:08,356 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2022-11-16 10:55:08,357 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 159 mSDsluCounter, 150 mSDsCounter, 0 mSdLazyCounter, 81 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 245 SdHoareTripleChecker+Invalid, 112 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 81 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:08,358 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [161 Valid, 245 Invalid, 112 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 81 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:08,359 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 133 states. [2022-11-16 10:55:08,409 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 133 to 127. [2022-11-16 10:55:08,410 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 127 states, 103 states have (on average 1.2718446601941749) internal successors, (131), 111 states have internal predecessors, (131), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-11-16 10:55:08,411 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 127 states to 127 states and 156 transitions. [2022-11-16 10:55:08,412 INFO L78 Accepts]: Start accepts. Automaton has 127 states and 156 transitions. Word has length 35 [2022-11-16 10:55:08,412 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:08,412 INFO L495 AbstractCegarLoop]: Abstraction has 127 states and 156 transitions. [2022-11-16 10:55:08,413 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:08,413 INFO L276 IsEmpty]: Start isEmpty. Operand 127 states and 156 transitions. [2022-11-16 10:55:08,414 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-11-16 10:55:08,415 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:08,415 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:08,415 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 10:55:08,415 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:08,416 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:08,416 INFO L85 PathProgramCache]: Analyzing trace with hash 585874736, now seen corresponding path program 1 times [2022-11-16 10:55:08,416 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:08,417 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [166984044] [2022-11-16 10:55:08,417 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:08,417 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:08,442 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,711 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:08,715 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:55:08,771 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:08,775 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:08,775 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:08,776 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [166984044] [2022-11-16 10:55:08,776 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [166984044] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:08,777 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:08,777 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 10:55:08,779 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1675298922] [2022-11-16 10:55:08,779 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:08,780 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:55:08,781 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:08,781 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:55:08,785 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:55:08,786 INFO L87 Difference]: Start difference. First operand 127 states and 156 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:09,185 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:09,186 INFO L93 Difference]: Finished difference Result 376 states and 485 transitions. [2022-11-16 10:55:09,187 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2022-11-16 10:55:09,187 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2022-11-16 10:55:09,189 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:09,202 INFO L225 Difference]: With dead ends: 376 [2022-11-16 10:55:09,202 INFO L226 Difference]: Without dead ends: 256 [2022-11-16 10:55:09,207 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 19 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=111, Unknown=0, NotChecked=0, Total=156 [2022-11-16 10:55:09,209 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 205 mSDsluCounter, 238 mSDsCounter, 0 mSdLazyCounter, 140 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 208 SdHoareTripleChecker+Valid, 332 SdHoareTripleChecker+Invalid, 174 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 140 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:09,210 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [208 Valid, 332 Invalid, 174 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 140 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:09,216 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 256 states. [2022-11-16 10:55:09,290 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 256 to 208. [2022-11-16 10:55:09,291 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 208 states, 169 states have (on average 1.272189349112426) internal successors, (215), 180 states have internal predecessors, (215), 18 states have call successors, (18), 18 states have call predecessors, (18), 20 states have return successors, (28), 18 states have call predecessors, (28), 18 states have call successors, (28) [2022-11-16 10:55:09,293 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 208 states to 208 states and 261 transitions. [2022-11-16 10:55:09,294 INFO L78 Accepts]: Start accepts. Automaton has 208 states and 261 transitions. Word has length 41 [2022-11-16 10:55:09,294 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:09,294 INFO L495 AbstractCegarLoop]: Abstraction has 208 states and 261 transitions. [2022-11-16 10:55:09,295 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:09,295 INFO L276 IsEmpty]: Start isEmpty. Operand 208 states and 261 transitions. [2022-11-16 10:55:09,296 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-11-16 10:55:09,297 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:09,297 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:09,297 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 10:55:09,298 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:09,298 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:09,299 INFO L85 PathProgramCache]: Analyzing trace with hash -1714947854, now seen corresponding path program 1 times [2022-11-16 10:55:09,299 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:09,299 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1210370072] [2022-11-16 10:55:09,299 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:09,300 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:09,324 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:09,467 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:09,471 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:09,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:55:09,481 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:09,482 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:09,483 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:09,483 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1210370072] [2022-11-16 10:55:09,483 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1210370072] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:09,483 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:09,484 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 10:55:09,484 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1094178977] [2022-11-16 10:55:09,484 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:09,485 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:55:09,485 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:09,485 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:55:09,485 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:55:09,486 INFO L87 Difference]: Start difference. First operand 208 states and 261 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:09,780 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:09,780 INFO L93 Difference]: Finished difference Result 407 states and 514 transitions. [2022-11-16 10:55:09,780 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-16 10:55:09,781 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2022-11-16 10:55:09,783 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:09,786 INFO L225 Difference]: With dead ends: 407 [2022-11-16 10:55:09,786 INFO L226 Difference]: Without dead ends: 206 [2022-11-16 10:55:09,789 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=40, Invalid=70, Unknown=0, NotChecked=0, Total=110 [2022-11-16 10:55:09,797 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 135 mSDsluCounter, 218 mSDsCounter, 0 mSdLazyCounter, 123 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 138 SdHoareTripleChecker+Valid, 286 SdHoareTripleChecker+Invalid, 143 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 123 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:09,800 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [138 Valid, 286 Invalid, 143 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 123 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:09,804 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 206 states. [2022-11-16 10:55:09,848 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 206 to 204. [2022-11-16 10:55:09,849 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 204 states, 165 states have (on average 1.2545454545454546) internal successors, (207), 176 states have internal predecessors, (207), 18 states have call successors, (18), 18 states have call predecessors, (18), 20 states have return successors, (28), 18 states have call predecessors, (28), 18 states have call successors, (28) [2022-11-16 10:55:09,852 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 204 states to 204 states and 253 transitions. [2022-11-16 10:55:09,853 INFO L78 Accepts]: Start accepts. Automaton has 204 states and 253 transitions. Word has length 41 [2022-11-16 10:55:09,853 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:09,853 INFO L495 AbstractCegarLoop]: Abstraction has 204 states and 253 transitions. [2022-11-16 10:55:09,853 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 10:55:09,854 INFO L276 IsEmpty]: Start isEmpty. Operand 204 states and 253 transitions. [2022-11-16 10:55:09,859 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-11-16 10:55:09,859 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:09,860 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:09,860 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 10:55:09,860 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:09,860 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:09,861 INFO L85 PathProgramCache]: Analyzing trace with hash -318970168, now seen corresponding path program 1 times [2022-11-16 10:55:09,861 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:09,861 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [496531174] [2022-11-16 10:55:09,861 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:09,861 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:09,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,014 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:10,015 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,024 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 10:55:10,031 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,082 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:55:10,083 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,088 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:10,088 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:10,088 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [496531174] [2022-11-16 10:55:10,088 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [496531174] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:10,088 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:10,089 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-16 10:55:10,089 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [365699066] [2022-11-16 10:55:10,089 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:10,090 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-16 10:55:10,090 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:10,091 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-16 10:55:10,092 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-11-16 10:55:10,092 INFO L87 Difference]: Start difference. First operand 204 states and 253 transitions. Second operand has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-16 10:55:10,531 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:10,531 INFO L93 Difference]: Finished difference Result 469 states and 581 transitions. [2022-11-16 10:55:10,532 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2022-11-16 10:55:10,532 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 45 [2022-11-16 10:55:10,533 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:10,536 INFO L225 Difference]: With dead ends: 469 [2022-11-16 10:55:10,536 INFO L226 Difference]: Without dead ends: 272 [2022-11-16 10:55:10,537 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 33 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=89, Invalid=183, Unknown=0, NotChecked=0, Total=272 [2022-11-16 10:55:10,547 INFO L413 NwaCegarLoop]: 58 mSDtfsCounter, 241 mSDsluCounter, 244 mSDsCounter, 0 mSdLazyCounter, 232 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 244 SdHoareTripleChecker+Valid, 302 SdHoareTripleChecker+Invalid, 266 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 232 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:10,548 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [244 Valid, 302 Invalid, 266 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 232 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:10,550 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 272 states. [2022-11-16 10:55:10,594 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 272 to 242. [2022-11-16 10:55:10,595 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 242 states, 198 states have (on average 1.2424242424242424) internal successors, (246), 213 states have internal predecessors, (246), 19 states have call successors, (19), 18 states have call predecessors, (19), 24 states have return successors, (33), 19 states have call predecessors, (33), 19 states have call successors, (33) [2022-11-16 10:55:10,599 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 242 states to 242 states and 298 transitions. [2022-11-16 10:55:10,599 INFO L78 Accepts]: Start accepts. Automaton has 242 states and 298 transitions. Word has length 45 [2022-11-16 10:55:10,599 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:10,599 INFO L495 AbstractCegarLoop]: Abstraction has 242 states and 298 transitions. [2022-11-16 10:55:10,600 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-16 10:55:10,600 INFO L276 IsEmpty]: Start isEmpty. Operand 242 states and 298 transitions. [2022-11-16 10:55:10,602 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-11-16 10:55:10,603 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:10,603 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:10,603 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 10:55:10,604 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:10,604 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:10,604 INFO L85 PathProgramCache]: Analyzing trace with hash -1598724404, now seen corresponding path program 1 times [2022-11-16 10:55:10,604 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:10,609 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1028705307] [2022-11-16 10:55:10,609 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:10,609 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:10,635 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,833 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:10,835 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,845 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 10:55:10,848 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,856 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 10:55:10,857 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:10,859 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:10,860 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:10,860 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1028705307] [2022-11-16 10:55:10,860 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1028705307] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:10,861 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:10,861 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 10:55:10,861 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1486550418] [2022-11-16 10:55:10,861 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:10,862 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 10:55:10,862 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:10,862 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 10:55:10,863 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:55:10,863 INFO L87 Difference]: Start difference. First operand 242 states and 298 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 10:55:11,354 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:11,354 INFO L93 Difference]: Finished difference Result 266 states and 323 transitions. [2022-11-16 10:55:11,355 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 18 states. [2022-11-16 10:55:11,355 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) Word has length 45 [2022-11-16 10:55:11,357 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:11,359 INFO L225 Difference]: With dead ends: 266 [2022-11-16 10:55:11,359 INFO L226 Difference]: Without dead ends: 264 [2022-11-16 10:55:11,360 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 70 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=106, Invalid=274, Unknown=0, NotChecked=0, Total=380 [2022-11-16 10:55:11,361 INFO L413 NwaCegarLoop]: 72 mSDtfsCounter, 194 mSDsluCounter, 309 mSDsCounter, 0 mSdLazyCounter, 263 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 195 SdHoareTripleChecker+Valid, 381 SdHoareTripleChecker+Invalid, 298 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 263 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:11,361 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [195 Valid, 381 Invalid, 298 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 263 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 10:55:11,362 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 264 states. [2022-11-16 10:55:11,399 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 264 to 242. [2022-11-16 10:55:11,400 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 242 states, 198 states have (on average 1.2272727272727273) internal successors, (243), 213 states have internal predecessors, (243), 19 states have call successors, (19), 18 states have call predecessors, (19), 24 states have return successors, (33), 19 states have call predecessors, (33), 19 states have call successors, (33) [2022-11-16 10:55:11,402 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 242 states to 242 states and 295 transitions. [2022-11-16 10:55:11,402 INFO L78 Accepts]: Start accepts. Automaton has 242 states and 295 transitions. Word has length 45 [2022-11-16 10:55:11,403 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:11,403 INFO L495 AbstractCegarLoop]: Abstraction has 242 states and 295 transitions. [2022-11-16 10:55:11,403 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-16 10:55:11,403 INFO L276 IsEmpty]: Start isEmpty. Operand 242 states and 295 transitions. [2022-11-16 10:55:11,404 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 10:55:11,404 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:11,404 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:11,405 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 10:55:11,405 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:11,405 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:11,406 INFO L85 PathProgramCache]: Analyzing trace with hash -1519506341, now seen corresponding path program 1 times [2022-11-16 10:55:11,406 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:11,406 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2031507220] [2022-11-16 10:55:11,406 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:11,407 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:11,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:11,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:11,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:11,561 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 10:55:11,564 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:11,575 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:11,576 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:11,576 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2031507220] [2022-11-16 10:55:11,576 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2031507220] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:11,576 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:11,576 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 10:55:11,576 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [25214844] [2022-11-16 10:55:11,577 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:11,577 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 10:55:11,577 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:11,578 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 10:55:11,578 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:55:11,578 INFO L87 Difference]: Start difference. First operand 242 states and 295 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,019 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:12,020 INFO L93 Difference]: Finished difference Result 473 states and 601 transitions. [2022-11-16 10:55:12,020 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2022-11-16 10:55:12,021 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-11-16 10:55:12,021 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:12,023 INFO L225 Difference]: With dead ends: 473 [2022-11-16 10:55:12,023 INFO L226 Difference]: Without dead ends: 316 [2022-11-16 10:55:12,024 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 13 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=63, Invalid=119, Unknown=0, NotChecked=0, Total=182 [2022-11-16 10:55:12,025 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 173 mSDsluCounter, 333 mSDsCounter, 0 mSdLazyCounter, 319 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 174 SdHoareTripleChecker+Valid, 421 SdHoareTripleChecker+Invalid, 355 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 319 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:12,025 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [174 Valid, 421 Invalid, 355 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 319 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 10:55:12,026 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 316 states. [2022-11-16 10:55:12,061 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 316 to 311. [2022-11-16 10:55:12,062 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 311 states, 254 states have (on average 1.2244094488188977) internal successors, (311), 271 states have internal predecessors, (311), 26 states have call successors, (26), 25 states have call predecessors, (26), 30 states have return successors, (51), 27 states have call predecessors, (51), 26 states have call successors, (51) [2022-11-16 10:55:12,065 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 311 states to 311 states and 388 transitions. [2022-11-16 10:55:12,065 INFO L78 Accepts]: Start accepts. Automaton has 311 states and 388 transitions. Word has length 47 [2022-11-16 10:55:12,065 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:12,065 INFO L495 AbstractCegarLoop]: Abstraction has 311 states and 388 transitions. [2022-11-16 10:55:12,066 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,066 INFO L276 IsEmpty]: Start isEmpty. Operand 311 states and 388 transitions. [2022-11-16 10:55:12,067 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 10:55:12,067 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:12,067 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:12,067 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-16 10:55:12,067 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:12,068 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:12,068 INFO L85 PathProgramCache]: Analyzing trace with hash 1292286815, now seen corresponding path program 1 times [2022-11-16 10:55:12,068 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:12,068 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [428420308] [2022-11-16 10:55:12,068 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:12,069 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:12,082 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,127 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:12,128 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,133 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 10:55:12,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,181 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:12,181 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:12,182 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [428420308] [2022-11-16 10:55:12,182 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [428420308] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:12,182 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:12,182 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 10:55:12,182 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [174703525] [2022-11-16 10:55:12,183 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:12,183 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 10:55:12,183 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:12,184 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 10:55:12,184 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 10:55:12,184 INFO L87 Difference]: Start difference. First operand 311 states and 388 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,530 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:12,530 INFO L93 Difference]: Finished difference Result 623 states and 787 transitions. [2022-11-16 10:55:12,531 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-16 10:55:12,531 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-11-16 10:55:12,532 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:12,534 INFO L225 Difference]: With dead ends: 623 [2022-11-16 10:55:12,534 INFO L226 Difference]: Without dead ends: 319 [2022-11-16 10:55:12,535 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=39, Invalid=71, Unknown=0, NotChecked=0, Total=110 [2022-11-16 10:55:12,536 INFO L413 NwaCegarLoop]: 63 mSDtfsCounter, 136 mSDsluCounter, 258 mSDsCounter, 0 mSdLazyCounter, 201 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 136 SdHoareTripleChecker+Valid, 321 SdHoareTripleChecker+Invalid, 228 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 201 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:12,537 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [136 Valid, 321 Invalid, 228 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 201 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:12,538 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 319 states. [2022-11-16 10:55:12,573 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 319 to 311. [2022-11-16 10:55:12,574 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 311 states, 254 states have (on average 1.2165354330708662) internal successors, (309), 271 states have internal predecessors, (309), 26 states have call successors, (26), 25 states have call predecessors, (26), 30 states have return successors, (51), 27 states have call predecessors, (51), 26 states have call successors, (51) [2022-11-16 10:55:12,576 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 311 states to 311 states and 386 transitions. [2022-11-16 10:55:12,576 INFO L78 Accepts]: Start accepts. Automaton has 311 states and 386 transitions. Word has length 47 [2022-11-16 10:55:12,577 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:12,577 INFO L495 AbstractCegarLoop]: Abstraction has 311 states and 386 transitions. [2022-11-16 10:55:12,577 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,577 INFO L276 IsEmpty]: Start isEmpty. Operand 311 states and 386 transitions. [2022-11-16 10:55:12,578 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-16 10:55:12,578 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:12,579 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:12,579 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-11-16 10:55:12,579 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:12,579 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:12,580 INFO L85 PathProgramCache]: Analyzing trace with hash -701857891, now seen corresponding path program 1 times [2022-11-16 10:55:12,580 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:12,580 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [249056314] [2022-11-16 10:55:12,580 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:12,580 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:12,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,647 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:12,648 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,653 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 10:55:12,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:12,685 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:12,685 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:12,685 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [249056314] [2022-11-16 10:55:12,685 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [249056314] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:12,686 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:12,686 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 10:55:12,686 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [224601636] [2022-11-16 10:55:12,686 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:12,687 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:55:12,687 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:12,688 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:55:12,688 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 10:55:12,688 INFO L87 Difference]: Start difference. First operand 311 states and 386 transitions. Second operand has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,944 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:12,944 INFO L93 Difference]: Finished difference Result 561 states and 704 transitions. [2022-11-16 10:55:12,945 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 10:55:12,945 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-11-16 10:55:12,946 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:12,948 INFO L225 Difference]: With dead ends: 561 [2022-11-16 10:55:12,948 INFO L226 Difference]: Without dead ends: 257 [2022-11-16 10:55:12,949 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-16 10:55:12,951 INFO L413 NwaCegarLoop]: 61 mSDtfsCounter, 140 mSDsluCounter, 194 mSDsCounter, 0 mSdLazyCounter, 156 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 140 SdHoareTripleChecker+Valid, 255 SdHoareTripleChecker+Invalid, 182 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 156 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:12,951 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [140 Valid, 255 Invalid, 182 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 156 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:12,952 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 257 states. [2022-11-16 10:55:12,983 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 257 to 255. [2022-11-16 10:55:12,984 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 255 states, 206 states have (on average 1.2087378640776698) internal successors, (249), 219 states have internal predecessors, (249), 23 states have call successors, (23), 22 states have call predecessors, (23), 25 states have return successors, (40), 23 states have call predecessors, (40), 23 states have call successors, (40) [2022-11-16 10:55:12,986 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 255 states to 255 states and 312 transitions. [2022-11-16 10:55:12,986 INFO L78 Accepts]: Start accepts. Automaton has 255 states and 312 transitions. Word has length 47 [2022-11-16 10:55:12,988 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:12,988 INFO L495 AbstractCegarLoop]: Abstraction has 255 states and 312 transitions. [2022-11-16 10:55:12,988 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 10:55:12,989 INFO L276 IsEmpty]: Start isEmpty. Operand 255 states and 312 transitions. [2022-11-16 10:55:12,990 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 83 [2022-11-16 10:55:12,990 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:12,991 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:12,991 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2022-11-16 10:55:12,991 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:12,992 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:12,992 INFO L85 PathProgramCache]: Analyzing trace with hash 2145897221, now seen corresponding path program 1 times [2022-11-16 10:55:12,992 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:12,992 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [702784318] [2022-11-16 10:55:12,992 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:12,993 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:13,019 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,181 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:13,183 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,197 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:13,201 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,247 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:55:13,251 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,269 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2022-11-16 10:55:13,271 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,274 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:13,275 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,277 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 12 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 10:55:13,277 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:13,277 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [702784318] [2022-11-16 10:55:13,278 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [702784318] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 10:55:13,278 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1130020133] [2022-11-16 10:55:13,278 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:13,278 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:55:13,279 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:55:13,286 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 10:55:13,336 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 10:55:13,456 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:13,460 INFO L263 TraceCheckSpWp]: Trace formula consists of 448 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-16 10:55:13,469 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 10:55:13,728 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 10:55:13,729 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 10:55:13,976 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 10:55:13,977 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1130020133] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 10:55:13,977 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 10:55:13,977 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-11-16 10:55:13,978 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [404140224] [2022-11-16 10:55:13,978 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 10:55:13,979 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-16 10:55:13,979 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:13,979 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-16 10:55:13,980 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-11-16 10:55:13,980 INFO L87 Difference]: Start difference. First operand 255 states and 312 transitions. Second operand has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-11-16 10:55:14,713 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:14,713 INFO L93 Difference]: Finished difference Result 590 states and 758 transitions. [2022-11-16 10:55:14,714 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-11-16 10:55:14,714 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 82 [2022-11-16 10:55:14,715 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:14,717 INFO L225 Difference]: With dead ends: 590 [2022-11-16 10:55:14,717 INFO L226 Difference]: Without dead ends: 383 [2022-11-16 10:55:14,719 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 200 GetRequests, 170 SyntacticMatches, 8 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 114 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=163, Invalid=389, Unknown=0, NotChecked=0, Total=552 [2022-11-16 10:55:14,720 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 247 mSDsluCounter, 431 mSDsCounter, 0 mSdLazyCounter, 404 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 251 SdHoareTripleChecker+Valid, 519 SdHoareTripleChecker+Invalid, 464 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 404 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:14,720 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [251 Valid, 519 Invalid, 464 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 404 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-16 10:55:14,721 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 383 states. [2022-11-16 10:55:14,765 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 383 to 350. [2022-11-16 10:55:14,767 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 350 states, 280 states have (on average 1.2107142857142856) internal successors, (339), 298 states have internal predecessors, (339), 33 states have call successors, (33), 32 states have call predecessors, (33), 36 states have return successors, (60), 31 states have call predecessors, (60), 33 states have call successors, (60) [2022-11-16 10:55:14,770 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 350 states to 350 states and 432 transitions. [2022-11-16 10:55:14,771 INFO L78 Accepts]: Start accepts. Automaton has 350 states and 432 transitions. Word has length 82 [2022-11-16 10:55:14,771 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:14,771 INFO L495 AbstractCegarLoop]: Abstraction has 350 states and 432 transitions. [2022-11-16 10:55:14,771 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-11-16 10:55:14,772 INFO L276 IsEmpty]: Start isEmpty. Operand 350 states and 432 transitions. [2022-11-16 10:55:14,781 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-11-16 10:55:14,781 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:14,781 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:14,794 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-16 10:55:14,987 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:55:14,988 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:14,989 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:14,989 INFO L85 PathProgramCache]: Analyzing trace with hash 1100274715, now seen corresponding path program 2 times [2022-11-16 10:55:14,989 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:14,989 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1373193353] [2022-11-16 10:55:14,989 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:14,989 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:15,023 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,234 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:15,235 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,246 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:15,252 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,274 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:55:15,277 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,291 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-11-16 10:55:15,299 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,441 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 10:55:15,443 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,445 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:15,449 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,450 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-11-16 10:55:15,451 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,458 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:15,460 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:15,461 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 54 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-11-16 10:55:15,461 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:15,462 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1373193353] [2022-11-16 10:55:15,462 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1373193353] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 10:55:15,462 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [612661253] [2022-11-16 10:55:15,462 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-11-16 10:55:15,462 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 10:55:15,463 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 10:55:15,464 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 10:55:15,487 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 10:55:15,633 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-11-16 10:55:15,633 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-11-16 10:55:15,637 INFO L263 TraceCheckSpWp]: Trace formula consists of 537 conjuncts, 10 conjunts are in the unsatisfiable core [2022-11-16 10:55:15,641 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 10:55:15,834 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-11-16 10:55:15,834 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 10:55:15,835 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [612661253] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:15,835 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 10:55:15,835 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2022-11-16 10:55:15,835 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [200927705] [2022-11-16 10:55:15,835 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:15,836 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 10:55:15,836 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:15,837 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 10:55:15,837 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2022-11-16 10:55:15,837 INFO L87 Difference]: Start difference. First operand 350 states and 432 transitions. Second operand has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-11-16 10:55:16,237 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:16,238 INFO L93 Difference]: Finished difference Result 931 states and 1192 transitions. [2022-11-16 10:55:16,238 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-16 10:55:16,239 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 117 [2022-11-16 10:55:16,239 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:16,243 INFO L225 Difference]: With dead ends: 931 [2022-11-16 10:55:16,243 INFO L226 Difference]: Without dead ends: 628 [2022-11-16 10:55:16,245 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 149 GetRequests, 130 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 45 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2022-11-16 10:55:16,246 INFO L413 NwaCegarLoop]: 140 mSDtfsCounter, 210 mSDsluCounter, 417 mSDsCounter, 0 mSdLazyCounter, 129 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 210 SdHoareTripleChecker+Valid, 557 SdHoareTripleChecker+Invalid, 150 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 129 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:16,246 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [210 Valid, 557 Invalid, 150 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 129 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:16,247 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 628 states. [2022-11-16 10:55:16,314 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 628 to 567. [2022-11-16 10:55:16,316 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 567 states, 454 states have (on average 1.2048458149779735) internal successors, (547), 479 states have internal predecessors, (547), 54 states have call successors, (54), 53 states have call predecessors, (54), 58 states have return successors, (95), 50 states have call predecessors, (95), 54 states have call successors, (95) [2022-11-16 10:55:16,320 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 567 states to 567 states and 696 transitions. [2022-11-16 10:55:16,321 INFO L78 Accepts]: Start accepts. Automaton has 567 states and 696 transitions. Word has length 117 [2022-11-16 10:55:16,321 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:16,321 INFO L495 AbstractCegarLoop]: Abstraction has 567 states and 696 transitions. [2022-11-16 10:55:16,321 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-11-16 10:55:16,322 INFO L276 IsEmpty]: Start isEmpty. Operand 567 states and 696 transitions. [2022-11-16 10:55:16,324 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-11-16 10:55:16,324 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 10:55:16,324 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:16,341 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 10:55:16,531 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable12 [2022-11-16 10:55:16,532 INFO L420 AbstractCegarLoop]: === Iteration 14 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 10:55:16,532 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 10:55:16,532 INFO L85 PathProgramCache]: Analyzing trace with hash 1976293721, now seen corresponding path program 1 times [2022-11-16 10:55:16,532 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 10:55:16,532 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1482048567] [2022-11-16 10:55:16,532 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 10:55:16,533 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 10:55:16,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,657 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-16 10:55:16,660 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,668 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-16 10:55:16,671 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,680 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-16 10:55:16,686 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,689 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-11-16 10:55:16,694 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,764 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 10:55:16,766 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,767 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:16,768 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,769 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-11-16 10:55:16,770 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,772 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 10:55:16,773 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 10:55:16,774 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2022-11-16 10:55:16,774 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 10:55:16,775 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1482048567] [2022-11-16 10:55:16,775 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1482048567] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 10:55:16,775 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 10:55:16,775 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-16 10:55:16,778 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1811201737] [2022-11-16 10:55:16,778 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 10:55:16,778 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-16 10:55:16,779 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 10:55:16,779 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-16 10:55:16,779 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-11-16 10:55:16,780 INFO L87 Difference]: Start difference. First operand 567 states and 696 transitions. Second operand has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-11-16 10:55:17,064 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 10:55:17,064 INFO L93 Difference]: Finished difference Result 777 states and 943 transitions. [2022-11-16 10:55:17,065 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-16 10:55:17,065 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 117 [2022-11-16 10:55:17,065 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 10:55:17,066 INFO L225 Difference]: With dead ends: 777 [2022-11-16 10:55:17,066 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 10:55:17,068 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2022-11-16 10:55:17,068 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 153 mSDsluCounter, 201 mSDsCounter, 0 mSdLazyCounter, 206 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 155 SdHoareTripleChecker+Valid, 254 SdHoareTripleChecker+Invalid, 233 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 206 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 10:55:17,069 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [155 Valid, 254 Invalid, 233 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 206 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 10:55:17,069 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 10:55:17,069 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 10:55:17,069 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 10:55:17,070 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 10:55:17,070 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 117 [2022-11-16 10:55:17,070 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 10:55:17,070 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 10:55:17,070 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-11-16 10:55:17,071 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 10:55:17,071 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 10:55:17,074 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 10:55:17,074 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable13 [2022-11-16 10:55:17,077 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 10:55:20,005 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2022-11-16 10:55:20,006 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2022-11-16 10:55:20,006 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 487 498) the Hoare annotation is: true [2022-11-16 10:55:20,006 INFO L899 garLoopResultBuilder]: For program point L491-1(lines 487 498) no Hoare annotation was computed. [2022-11-16 10:55:20,006 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 487 498) no Hoare annotation was computed. [2022-11-16 10:55:20,007 INFO L895 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,007 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 707 730) no Hoare annotation was computed. [2022-11-16 10:55:20,007 INFO L899 garLoopResultBuilder]: For program point L449(line 449) no Hoare annotation was computed. [2022-11-16 10:55:20,007 INFO L895 garLoopResultBuilder]: At program point L536(lines 531 539) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse1 .cse2 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_getWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (and (= |old(~waterLevel~0)| ~waterLevel~0) (<= 2 |timeShift_getWaterLevel_#res#1|)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse1 (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse2 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-11-16 10:55:20,007 INFO L895 garLoopResultBuilder]: At program point L821(lines 816 823) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse0 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,008 INFO L895 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) (or .cse0 .cse2 (not (= |old(~waterLevel~0)| 1)) .cse1) (or .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,008 INFO L895 garLoopResultBuilder]: At program point L784-1(lines 765 789) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (= 1 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not .cse4)) (.cse3 (and (<= 2 ~waterLevel~0) .cse4 .cse1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 .cse1) .cse2 .cse3 (not (<= 1 |old(~waterLevel~0)|))) (or (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse0 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse2 .cse3 (not (<= 2 |old(~waterLevel~0)|)))))) [2022-11-16 10:55:20,008 INFO L899 garLoopResultBuilder]: For program point L718-1(lines 718 724) no Hoare annotation was computed. [2022-11-16 10:55:20,008 INFO L899 garLoopResultBuilder]: For program point L908(lines 908 912) no Hoare annotation was computed. [2022-11-16 10:55:20,008 INFO L899 garLoopResultBuilder]: For program point L908-2(lines 908 912) no Hoare annotation was computed. [2022-11-16 10:55:20,008 INFO L895 garLoopResultBuilder]: At program point L450(lines 445 452) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,009 INFO L899 garLoopResultBuilder]: For program point L467(lines 467 471) no Hoare annotation was computed. [2022-11-16 10:55:20,009 INFO L895 garLoopResultBuilder]: At program point L467-2(lines 463 474) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,009 INFO L899 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2022-11-16 10:55:20,009 INFO L899 garLoopResultBuilder]: For program point L773(lines 773 781) no Hoare annotation was computed. [2022-11-16 10:55:20,009 INFO L899 garLoopResultBuilder]: For program point L769(lines 769 786) no Hoare annotation was computed. [2022-11-16 10:55:20,009 INFO L895 garLoopResultBuilder]: At program point L914(lines 899 917) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,010 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 707 730) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0 (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))))) [2022-11-16 10:55:20,010 INFO L895 garLoopResultBuilder]: At program point L559(lines 554 562) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,010 INFO L899 garLoopResultBuilder]: For program point L431(lines 431 437) no Hoare annotation was computed. [2022-11-16 10:55:20,010 INFO L899 garLoopResultBuilder]: For program point L427(lines 427 440) no Hoare annotation was computed. [2022-11-16 10:55:20,010 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2022-11-16 10:55:20,010 INFO L895 garLoopResultBuilder]: At program point L427-1(lines 419 443) the Hoare annotation is: (let ((.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (= 1 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not .cse6)) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (and (<= 2 ~waterLevel~0) .cse6 .cse2 (<= 2 |timeShift_getWaterLevel_#res#1|) (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|))) (.cse5 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~waterLevel~0)|)) .cse4) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 .cse3 .cse4 .cse5) (or .cse3 (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse1 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_getWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse4 .cse5)))) [2022-11-16 10:55:20,011 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 449) no Hoare annotation was computed. [2022-11-16 10:55:20,011 INFO L895 garLoopResultBuilder]: At program point L840(lines 835 843) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,011 INFO L899 garLoopResultBuilder]: For program point L577(line 577) no Hoare annotation was computed. [2022-11-16 10:55:20,011 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 566 595) no Hoare annotation was computed. [2022-11-16 10:55:20,011 INFO L902 garLoopResultBuilder]: At program point L576-2(lines 576 590) the Hoare annotation is: true [2022-11-16 10:55:20,011 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 566 595) the Hoare annotation is: true [2022-11-16 10:55:20,011 INFO L902 garLoopResultBuilder]: At program point L572(line 572) the Hoare annotation is: true [2022-11-16 10:55:20,011 INFO L899 garLoopResultBuilder]: For program point L572-1(line 572) no Hoare annotation was computed. [2022-11-16 10:55:20,012 INFO L902 garLoopResultBuilder]: At program point L591(lines 566 595) the Hoare annotation is: true [2022-11-16 10:55:20,012 INFO L899 garLoopResultBuilder]: For program point L587(line 587) no Hoare annotation was computed. [2022-11-16 10:55:20,012 INFO L899 garLoopResultBuilder]: For program point L580(lines 580 584) no Hoare annotation was computed. [2022-11-16 10:55:20,012 INFO L902 garLoopResultBuilder]: At program point L580-1(lines 580 584) the Hoare annotation is: true [2022-11-16 10:55:20,012 INFO L895 garLoopResultBuilder]: At program point L923(lines 918 925) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 10:55:20,012 INFO L895 garLoopResultBuilder]: At program point L985(lines 936 986) the Hoare annotation is: false [2022-11-16 10:55:20,012 INFO L895 garLoopResultBuilder]: At program point L696(lines 691 699) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:55:20,012 INFO L895 garLoopResultBuilder]: At program point L688(lines 684 690) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point L957(lines 957 963) no Hoare annotation was computed. [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point L957-1(lines 957 963) no Hoare annotation was computed. [2022-11-16 10:55:20,013 INFO L895 garLoopResultBuilder]: At program point L982(lines 937 984) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 10:55:20,013 INFO L895 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 10:55:20,013 INFO L899 garLoopResultBuilder]: For program point L652(lines 652 659) no Hoare annotation was computed. [2022-11-16 10:55:20,014 INFO L899 garLoopResultBuilder]: For program point L652-2(lines 652 659) no Hoare annotation was computed. [2022-11-16 10:55:20,014 INFO L895 garLoopResultBuilder]: At program point L681(lines 677 683) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:55:20,014 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 10:55:20,014 INFO L902 garLoopResultBuilder]: At program point L636(lines 629 638) the Hoare annotation is: true [2022-11-16 10:55:20,014 INFO L902 garLoopResultBuilder]: At program point L661(lines 642 664) the Hoare annotation is: true [2022-11-16 10:55:20,014 INFO L899 garLoopResultBuilder]: For program point L975(lines 975 979) no Hoare annotation was computed. [2022-11-16 10:55:20,014 INFO L895 garLoopResultBuilder]: At program point L975-2(lines 967 980) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 10:55:20,015 INFO L899 garLoopResultBuilder]: For program point L938(lines 937 984) no Hoare annotation was computed. [2022-11-16 10:55:20,015 INFO L899 garLoopResultBuilder]: For program point L967(lines 967 980) no Hoare annotation was computed. [2022-11-16 10:55:20,015 INFO L895 garLoopResultBuilder]: At program point L959(line 959) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-16 10:55:20,016 INFO L902 garLoopResultBuilder]: At program point L988(lines 927 992) the Hoare annotation is: true [2022-11-16 10:55:20,016 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2022-11-16 10:55:20,016 INFO L899 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2022-11-16 10:55:20,016 INFO L895 garLoopResultBuilder]: At program point L625(lines 621 627) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 10:55:20,016 INFO L899 garLoopResultBuilder]: For program point L939(lines 939 943) no Hoare annotation was computed. [2022-11-16 10:55:20,017 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 739 763) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (not (<= 2 ~waterLevel~0))))) [2022-11-16 10:55:20,017 INFO L895 garLoopResultBuilder]: At program point L795(lines 790 797) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) (not (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))))) [2022-11-16 10:55:20,018 INFO L895 garLoopResultBuilder]: At program point L504(lines 499 507) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 0) (not (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))) (not (<= 2 ~waterLevel~0))))) [2022-11-16 10:55:20,018 INFO L895 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-16 10:55:20,018 INFO L899 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2022-11-16 10:55:20,018 INFO L899 garLoopResultBuilder]: For program point L806(lines 806 812) no Hoare annotation was computed. [2022-11-16 10:55:20,019 INFO L895 garLoopResultBuilder]: At program point L806-2(lines 799 815) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) (not (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))))) [2022-11-16 10:55:20,020 INFO L899 garLoopResultBuilder]: For program point L544(lines 544 550) no Hoare annotation was computed. [2022-11-16 10:55:20,020 INFO L895 garLoopResultBuilder]: At program point L895(lines 880 898) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (.cse6 (<= 2 ~waterLevel~0)) (.cse7 (= 1 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse7)) (.cse5 (and .cse2 .cse3 (not .cse4) .cse6 .cse7 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1|)))) (and (or .cse0 .cse1 (and .cse2 .cse3 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 1) .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)) (not (<= 1 ~waterLevel~0)) .cse5) (or .cse0 .cse1 (not .cse6) .cse5)))) [2022-11-16 10:55:20,021 INFO L895 garLoopResultBuilder]: At program point L831(lines 824 834) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 0) (not (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))) (not (<= 2 ~waterLevel~0))))) [2022-11-16 10:55:20,021 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2022-11-16 10:55:20,022 INFO L899 garLoopResultBuilder]: For program point L889(lines 889 893) no Hoare annotation was computed. [2022-11-16 10:55:20,022 INFO L899 garLoopResultBuilder]: For program point L889-2(lines 889 893) no Hoare annotation was computed. [2022-11-16 10:55:20,022 INFO L895 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0))) (or .cse0 .cse1 (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1))))) [2022-11-16 10:55:20,022 INFO L899 garLoopResultBuilder]: For program point L747(lines 747 755) no Hoare annotation was computed. [2022-11-16 10:55:20,022 INFO L899 garLoopResultBuilder]: For program point L743(lines 743 760) no Hoare annotation was computed. [2022-11-16 10:55:20,022 INFO L895 garLoopResultBuilder]: At program point L549(lines 540 553) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1))))) [2022-11-16 10:55:20,023 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 475 486) no Hoare annotation was computed. [2022-11-16 10:55:20,023 INFO L899 garLoopResultBuilder]: For program point L479-1(lines 475 486) no Hoare annotation was computed. [2022-11-16 10:55:20,023 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 475 486) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-16 10:55:20,026 INFO L444 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 10:55:20,029 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 10:55:20,073 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 10:55:20 BoogieIcfgContainer [2022-11-16 10:55:20,073 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 10:55:20,074 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 10:55:20,074 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 10:55:20,074 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 10:55:20,074 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 10:55:06" (3/4) ... [2022-11-16 10:55:20,078 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 10:55:20,091 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 10:55:20,091 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 10:55:20,091 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 10:55:20,091 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 10:55:20,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 10:55:20,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 10:55:20,108 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-11-16 10:55:20,109 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 10:55:20,110 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 10:55:20,110 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 10:55:20,111 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 10:55:20,111 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 10:55:20,112 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 10:55:20,147 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,149 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) && (((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || !(1 == systemActive)) || ((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,151 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || ((((((((\result == 0 && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || (\old(waterLevel) == waterLevel && 2 <= \result)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-11-16 10:55:20,152 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || !(2 <= \old(waterLevel)))) && (((!(1 == systemActive) || ((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,152 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,152 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || (pumpRunning == 0 && \result == 0)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && \result == 1)) [2022-11-16 10:55:20,152 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,153 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,153 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && tmp == 1) && \result == 0) && \result == 1)) || !(1 <= waterLevel)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && !(\result == 0)) && 2 <= waterLevel) && 1 == systemActive) && 1 <= tmp___0)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && !(\result == 0)) && 2 <= waterLevel) && 1 == systemActive) && 1 <= tmp___0)) [2022-11-16 10:55:20,153 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,154 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || !(1 == systemActive)) || !(2 <= \old(waterLevel))) [2022-11-16 10:55:20,155 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(tmp == 0))) || !(2 <= waterLevel)) [2022-11-16 10:55:20,155 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(tmp == 0))) || !(2 <= waterLevel)) [2022-11-16 10:55:20,155 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || !(tmp == 0)) [2022-11-16 10:55:20,160 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || !(tmp == 0)) [2022-11-16 10:55:20,221 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 10:55:20,221 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 10:55:20,222 INFO L158 Benchmark]: Toolchain (without parser) took 15226.00ms. Allocated memory was 157.3MB in the beginning and 255.9MB in the end (delta: 98.6MB). Free memory was 121.2MB in the beginning and 172.9MB in the end (delta: -51.6MB). Peak memory consumption was 47.3MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,223 INFO L158 Benchmark]: CDTParser took 0.34ms. Allocated memory is still 157.3MB. Free memory was 131.5MB in the beginning and 131.5MB in the end (delta: 28.6kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 10:55:20,223 INFO L158 Benchmark]: CACSL2BoogieTranslator took 637.36ms. Allocated memory is still 157.3MB. Free memory was 120.9MB in the beginning and 121.9MB in the end (delta: -998.6kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,223 INFO L158 Benchmark]: Boogie Procedure Inliner took 83.44ms. Allocated memory is still 157.3MB. Free memory was 121.9MB in the beginning and 119.5MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,224 INFO L158 Benchmark]: Boogie Preprocessor took 30.97ms. Allocated memory is still 157.3MB. Free memory was 119.5MB in the beginning and 117.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,224 INFO L158 Benchmark]: RCFGBuilder took 796.76ms. Allocated memory is still 157.3MB. Free memory was 117.8MB in the beginning and 98.5MB in the end (delta: 19.3MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,225 INFO L158 Benchmark]: TraceAbstraction took 13517.01ms. Allocated memory was 157.3MB in the beginning and 255.9MB in the end (delta: 98.6MB). Free memory was 97.6MB in the beginning and 179.2MB in the end (delta: -81.6MB). Peak memory consumption was 117.0MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,225 INFO L158 Benchmark]: Witness Printer took 147.87ms. Allocated memory is still 255.9MB. Free memory was 179.2MB in the beginning and 172.9MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 10:55:20,227 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.34ms. Allocated memory is still 157.3MB. Free memory was 131.5MB in the beginning and 131.5MB in the end (delta: 28.6kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 637.36ms. Allocated memory is still 157.3MB. Free memory was 120.9MB in the beginning and 121.9MB in the end (delta: -998.6kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 83.44ms. Allocated memory is still 157.3MB. Free memory was 121.9MB in the beginning and 119.5MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 30.97ms. Allocated memory is still 157.3MB. Free memory was 119.5MB in the beginning and 117.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 796.76ms. Allocated memory is still 157.3MB. Free memory was 117.8MB in the beginning and 98.5MB in the end (delta: 19.3MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 13517.01ms. Allocated memory was 157.3MB in the beginning and 255.9MB in the end (delta: 98.6MB). Free memory was 97.6MB in the beginning and 179.2MB in the end (delta: -81.6MB). Peak memory consumption was 117.0MB. Max. memory is 16.1GB. * Witness Printer took 147.87ms. Allocated memory is still 255.9MB. Free memory was 179.2MB in the beginning and 172.9MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 449]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 87 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 13.4s, OverallIterations: 14, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 4.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2097 SdHoareTripleChecker+Valid, 2.6s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2075 mSDsluCounter, 4229 SdHoareTripleChecker+Invalid, 2.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3064 mSDsCounter, 352 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2256 IncrementalHoareTripleChecker+Invalid, 2608 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 352 mSolverCounterUnsat, 1165 mSDtfsCounter, 2256 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 529 GetRequests, 380 SyntacticMatches, 11 SemanticMatches, 138 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 318 ImplicationChecksByTransitivity, 1.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=567occurred in iteration=13, InterpolantAutomatonStates: 134, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 14 MinimizatonAttempts, 217 StatesRemovedByMinimization, 10 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 42 LocationsWithAnnotation, 1337 PreInvPairs, 1426 NumberOfFragments, 1136 HoareAnnotationTreeSize, 1337 FomulaSimplifications, 1277 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 42 FomulaSimplificationsInter, 3537 FormulaSimplificationTreeSizeReductionInter, 2.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 3.4s InterpolantComputationTime, 927 NumberOfCodeBlocks, 927 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 992 ConstructedInterpolants, 0 QuantifiedInterpolants, 1903 SizeOfPredicates, 8 NumberOfNonLiveVariables, 985 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 17 InterpolantComputations, 13 PerfectInterpolantSequences, 264/294 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || !(1 == systemActive)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || !(2 <= \old(waterLevel)))) && (((!(1 == systemActive) || ((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || ((((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: ((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: ((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 927]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 799]: Loop Invariant Derived loop invariant: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || !(tmp == 0)) - InvariantResult [Line: 642]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 576]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 463]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 835]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 691]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 554]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 790]: Loop Invariant Derived loop invariant: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || !(tmp == 0)) - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && tmp == 1) && \result == 0) && \result == 1)) || !(1 <= waterLevel)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && !(\result == 0)) && 2 <= waterLevel) && 1 == systemActive) && 1 <= tmp___0)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && !(\result == 0)) && 2 <= waterLevel) && 1 == systemActive) && 1 <= tmp___0)) - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || ((((((((\result == 0 && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || (\old(waterLevel) == waterLevel && 2 <= \result)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 621]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 445]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 499]: Loop Invariant Derived loop invariant: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(tmp == 0))) || !(2 <= waterLevel)) - InvariantResult [Line: 899]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 629]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 765]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) && (((((((((\result == 0 && pumpRunning == 0) && 1 <= \result) && 1 <= tmp) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || !(1 == systemActive)) || ((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 677]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(tmp == 0))) || !(2 <= waterLevel)) - InvariantResult [Line: 936]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 566]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 540]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 <= waterLevel)) || (pumpRunning == 0 && \result == 0)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && \result == 1)) - InvariantResult [Line: 684]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 RESULT: Ultimate proved your program to be correct! [2022-11-16 10:55:20,283 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_f298eb29-d309-4daa-9569-bfd45b23f417/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE