./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 68c6d60a43782147acd714b0904a144255717c2aa47fb6b6f8991672a1483369 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 12:10:05,869 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 12:10:05,872 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 12:10:05,917 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 12:10:05,918 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 12:10:05,919 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 12:10:05,920 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 12:10:05,922 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 12:10:05,924 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 12:10:05,925 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 12:10:05,926 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 12:10:05,933 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 12:10:05,934 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 12:10:05,939 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 12:10:05,942 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 12:10:05,944 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 12:10:05,946 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 12:10:05,948 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 12:10:05,952 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 12:10:05,960 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 12:10:05,961 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 12:10:05,963 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 12:10:05,966 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 12:10:05,967 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 12:10:05,975 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 12:10:05,976 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 12:10:05,976 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 12:10:05,978 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 12:10:05,978 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 12:10:05,979 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 12:10:05,980 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 12:10:05,981 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 12:10:05,982 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 12:10:05,984 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 12:10:05,985 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 12:10:05,985 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 12:10:05,986 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 12:10:05,986 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 12:10:05,986 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 12:10:05,987 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 12:10:05,988 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 12:10:05,989 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-16 12:10:06,030 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 12:10:06,031 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 12:10:06,031 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 12:10:06,032 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 12:10:06,032 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 12:10:06,032 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 12:10:06,033 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-16 12:10:06,033 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-16 12:10:06,033 INFO L138 SettingsManager]: * Use SBE=true [2022-11-16 12:10:06,034 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 12:10:06,035 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 12:10:06,035 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 12:10:06,035 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 12:10:06,035 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 12:10:06,035 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 12:10:06,036 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 12:10:06,037 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 12:10:06,037 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-16 12:10:06,037 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 12:10:06,037 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 12:10:06,037 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-16 12:10:06,038 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-16 12:10:06,039 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 12:10:06,039 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 68c6d60a43782147acd714b0904a144255717c2aa47fb6b6f8991672a1483369 [2022-11-16 12:10:06,356 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 12:10:06,385 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 12:10:06,387 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 12:10:06,388 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 12:10:06,389 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 12:10:06,390 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/../../sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c [2022-11-16 12:10:06,455 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/data/ead0a37cd/c084ab1aae83429a8d0b93cfa22ffeef/FLAG9c6c30696 [2022-11-16 12:10:07,008 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 12:10:07,008 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c [2022-11-16 12:10:07,025 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/data/ead0a37cd/c084ab1aae83429a8d0b93cfa22ffeef/FLAG9c6c30696 [2022-11-16 12:10:07,291 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/data/ead0a37cd/c084ab1aae83429a8d0b93cfa22ffeef [2022-11-16 12:10:07,296 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 12:10:07,299 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 12:10:07,303 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 12:10:07,303 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 12:10:07,307 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 12:10:07,308 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,311 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@65b8a439 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07, skipping insertion in model container [2022-11-16 12:10:07,311 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,320 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 12:10:07,377 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 12:10:07,584 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c[1605,1618] [2022-11-16 12:10:07,700 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 12:10:07,719 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 12:10:07,745 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/sv-benchmarks/c/product-lines/minepump_spec5_product38.cil.c[1605,1618] [2022-11-16 12:10:07,840 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 12:10:07,868 INFO L208 MainTranslator]: Completed translation [2022-11-16 12:10:07,868 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07 WrapperNode [2022-11-16 12:10:07,869 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 12:10:07,870 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 12:10:07,870 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 12:10:07,870 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 12:10:07,878 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,904 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,949 INFO L138 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 259 [2022-11-16 12:10:07,951 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 12:10:07,952 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 12:10:07,952 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 12:10:07,952 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 12:10:07,961 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,961 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,977 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,980 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:07,984 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:08,007 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:08,008 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:08,010 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:08,012 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 12:10:08,013 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 12:10:08,013 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 12:10:08,013 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 12:10:08,021 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (1/1) ... [2022-11-16 12:10:08,029 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 12:10:08,046 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 12:10:08,073 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 12:10:08,106 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 12:10:08,125 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 12:10:08,125 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 12:10:08,125 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 12:10:08,126 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 12:10:08,126 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 12:10:08,126 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 12:10:08,126 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 12:10:08,126 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 12:10:08,126 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 12:10:08,126 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 12:10:08,127 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 12:10:08,127 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-16 12:10:08,127 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-16 12:10:08,127 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 12:10:08,127 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 12:10:08,127 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 12:10:08,127 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 12:10:08,127 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 12:10:08,208 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 12:10:08,211 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 12:10:08,600 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 12:10:08,608 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 12:10:08,608 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 12:10:08,610 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:10:08 BoogieIcfgContainer [2022-11-16 12:10:08,611 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 12:10:08,613 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 12:10:08,613 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 12:10:08,617 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 12:10:08,617 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 12:10:07" (1/3) ... [2022-11-16 12:10:08,618 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@49f7db34 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 12:10:08, skipping insertion in model container [2022-11-16 12:10:08,618 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 12:10:07" (2/3) ... [2022-11-16 12:10:08,619 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@49f7db34 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 12:10:08, skipping insertion in model container [2022-11-16 12:10:08,619 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:10:08" (3/3) ... [2022-11-16 12:10:08,620 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product38.cil.c [2022-11-16 12:10:08,640 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 12:10:08,641 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 12:10:08,725 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 12:10:08,741 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@7e1cb16c, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 12:10:08,741 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 12:10:08,748 INFO L276 IsEmpty]: Start isEmpty. Operand has 91 states, 70 states have (on average 1.3714285714285714) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-16 12:10:08,764 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-16 12:10:08,764 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:08,765 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:08,766 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:08,774 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:08,774 INFO L85 PathProgramCache]: Analyzing trace with hash 849031785, now seen corresponding path program 1 times [2022-11-16 12:10:08,794 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:08,794 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1039468179] [2022-11-16 12:10:08,795 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:08,796 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:08,926 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,061 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-11-16 12:10:09,070 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,081 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-11-16 12:10:09,089 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,094 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:09,097 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:09,097 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1039468179] [2022-11-16 12:10:09,098 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1039468179] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:09,099 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:09,099 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 12:10:09,107 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [943596442] [2022-11-16 12:10:09,108 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:09,114 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 12:10:09,115 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:09,151 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 12:10:09,152 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 12:10:09,155 INFO L87 Difference]: Start difference. First operand has 91 states, 70 states have (on average 1.3714285714285714) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 12:10:09,218 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:09,222 INFO L93 Difference]: Finished difference Result 173 states and 234 transitions. [2022-11-16 12:10:09,223 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 12:10:09,224 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-11-16 12:10:09,225 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:09,238 INFO L225 Difference]: With dead ends: 173 [2022-11-16 12:10:09,238 INFO L226 Difference]: Without dead ends: 82 [2022-11-16 12:10:09,243 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 12:10:09,250 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 114 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:09,253 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 114 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:10:09,273 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 82 states. [2022-11-16 12:10:09,308 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 82 to 82. [2022-11-16 12:10:09,310 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 82 states, 63 states have (on average 1.3015873015873016) internal successors, (82), 70 states have internal predecessors, (82), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 12:10:09,321 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 82 states to 82 states and 105 transitions. [2022-11-16 12:10:09,323 INFO L78 Accepts]: Start accepts. Automaton has 82 states and 105 transitions. Word has length 32 [2022-11-16 12:10:09,323 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:09,324 INFO L495 AbstractCegarLoop]: Abstraction has 82 states and 105 transitions. [2022-11-16 12:10:09,325 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 12:10:09,325 INFO L276 IsEmpty]: Start isEmpty. Operand 82 states and 105 transitions. [2022-11-16 12:10:09,333 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-16 12:10:09,333 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:09,333 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:09,334 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 12:10:09,334 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:09,336 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:09,337 INFO L85 PathProgramCache]: Analyzing trace with hash 79054015, now seen corresponding path program 1 times [2022-11-16 12:10:09,337 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:09,338 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1438288510] [2022-11-16 12:10:09,338 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:09,338 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:09,393 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,644 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-11-16 12:10:09,646 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,648 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-11-16 12:10:09,649 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,651 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:09,655 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:09,656 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1438288510] [2022-11-16 12:10:09,656 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1438288510] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:09,656 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:09,657 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 12:10:09,657 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2125240440] [2022-11-16 12:10:09,657 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:09,658 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 12:10:09,660 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:09,660 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 12:10:09,662 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:10:09,662 INFO L87 Difference]: Start difference. First operand 82 states and 105 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 12:10:09,692 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:09,693 INFO L93 Difference]: Finished difference Result 128 states and 164 transitions. [2022-11-16 12:10:09,694 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 12:10:09,694 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-11-16 12:10:09,695 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:09,699 INFO L225 Difference]: With dead ends: 128 [2022-11-16 12:10:09,700 INFO L226 Difference]: Without dead ends: 73 [2022-11-16 12:10:09,708 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:10:09,710 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 13 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 167 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:09,712 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 167 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 12:10:09,715 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-11-16 12:10:09,724 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-11-16 12:10:09,728 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.3157894736842106) internal successors, (75), 64 states have internal predecessors, (75), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-16 12:10:09,734 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 93 transitions. [2022-11-16 12:10:09,735 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 93 transitions. Word has length 33 [2022-11-16 12:10:09,735 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:09,736 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 93 transitions. [2022-11-16 12:10:09,737 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 12:10:09,737 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 93 transitions. [2022-11-16 12:10:09,743 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-16 12:10:09,745 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:09,745 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:09,746 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 12:10:09,746 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:09,747 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:09,747 INFO L85 PathProgramCache]: Analyzing trace with hash 321911882, now seen corresponding path program 1 times [2022-11-16 12:10:09,748 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:09,748 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2049692635] [2022-11-16 12:10:09,748 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:09,749 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:09,787 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,913 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:09,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,918 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-11-16 12:10:09,920 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:09,922 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:09,923 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:09,923 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2049692635] [2022-11-16 12:10:09,923 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2049692635] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:09,923 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:09,924 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 12:10:09,924 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2083776163] [2022-11-16 12:10:09,924 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:09,925 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 12:10:09,925 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:09,925 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 12:10:09,926 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 12:10:09,926 INFO L87 Difference]: Start difference. First operand 73 states and 93 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 12:10:10,034 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:10,034 INFO L93 Difference]: Finished difference Result 138 states and 179 transitions. [2022-11-16 12:10:10,049 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 12:10:10,050 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-11-16 12:10:10,050 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:10,051 INFO L225 Difference]: With dead ends: 138 [2022-11-16 12:10:10,051 INFO L226 Difference]: Without dead ends: 73 [2022-11-16 12:10:10,052 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-16 12:10:10,053 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 116 mSDsluCounter, 138 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 116 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:10,053 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [116 Valid, 224 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 12:10:10,054 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-11-16 12:10:10,063 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-11-16 12:10:10,064 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-16 12:10:10,064 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 92 transitions. [2022-11-16 12:10:10,065 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 92 transitions. Word has length 38 [2022-11-16 12:10:10,066 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:10,069 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 92 transitions. [2022-11-16 12:10:10,070 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 12:10:10,070 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 92 transitions. [2022-11-16 12:10:10,071 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-16 12:10:10,071 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:10,072 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:10,072 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 12:10:10,072 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:10,073 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:10,073 INFO L85 PathProgramCache]: Analyzing trace with hash 1433797075, now seen corresponding path program 1 times [2022-11-16 12:10:10,073 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:10,073 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [255141441] [2022-11-16 12:10:10,073 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:10,074 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:10,119 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,266 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:10,278 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,283 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-11-16 12:10:10,289 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,291 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:10,292 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:10,292 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [255141441] [2022-11-16 12:10:10,292 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [255141441] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:10,292 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:10,293 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 12:10:10,293 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [666496421] [2022-11-16 12:10:10,293 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:10,294 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 12:10:10,294 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:10,294 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 12:10:10,294 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:10:10,295 INFO L87 Difference]: Start difference. First operand 73 states and 92 transitions. Second operand has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 12:10:10,370 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:10,372 INFO L93 Difference]: Finished difference Result 186 states and 241 transitions. [2022-11-16 12:10:10,373 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 12:10:10,373 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2022-11-16 12:10:10,374 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:10,376 INFO L225 Difference]: With dead ends: 186 [2022-11-16 12:10:10,378 INFO L226 Difference]: Without dead ends: 121 [2022-11-16 12:10:10,379 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 12:10:10,381 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 54 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 54 SdHoareTripleChecker+Valid, 175 SdHoareTripleChecker+Invalid, 15 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:10,384 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [54 Valid, 175 Invalid, 15 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 12:10:10,387 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 121 states. [2022-11-16 12:10:10,406 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 121 to 119. [2022-11-16 12:10:10,406 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 119 states, 92 states have (on average 1.2826086956521738) internal successors, (118), 99 states have internal predecessors, (118), 14 states have call successors, (14), 12 states have call predecessors, (14), 12 states have return successors, (18), 14 states have call predecessors, (18), 14 states have call successors, (18) [2022-11-16 12:10:10,408 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 119 states to 119 states and 150 transitions. [2022-11-16 12:10:10,408 INFO L78 Accepts]: Start accepts. Automaton has 119 states and 150 transitions. Word has length 44 [2022-11-16 12:10:10,408 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:10,409 INFO L495 AbstractCegarLoop]: Abstraction has 119 states and 150 transitions. [2022-11-16 12:10:10,409 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 12:10:10,409 INFO L276 IsEmpty]: Start isEmpty. Operand 119 states and 150 transitions. [2022-11-16 12:10:10,410 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-16 12:10:10,410 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:10,411 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:10,411 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 12:10:10,411 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:10,411 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:10,412 INFO L85 PathProgramCache]: Analyzing trace with hash -464428248, now seen corresponding path program 1 times [2022-11-16 12:10:10,412 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:10,412 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1988611783] [2022-11-16 12:10:10,412 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:10,413 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:10,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,489 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:10,491 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,495 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-16 12:10:10,498 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,528 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-16 12:10:10,530 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,531 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:10,532 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:10,532 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1988611783] [2022-11-16 12:10:10,532 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1988611783] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:10,532 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:10,533 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 12:10:10,533 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1302721433] [2022-11-16 12:10:10,533 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:10,534 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 12:10:10,534 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:10,534 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 12:10:10,534 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 12:10:10,535 INFO L87 Difference]: Start difference. First operand 119 states and 150 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:10,759 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:10,760 INFO L93 Difference]: Finished difference Result 262 states and 338 transitions. [2022-11-16 12:10:10,760 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 12:10:10,761 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-16 12:10:10,761 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:10,767 INFO L225 Difference]: With dead ends: 262 [2022-11-16 12:10:10,767 INFO L226 Difference]: Without dead ends: 151 [2022-11-16 12:10:10,768 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-16 12:10:10,772 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 63 mSDsluCounter, 286 mSDsCounter, 0 mSdLazyCounter, 117 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 66 SdHoareTripleChecker+Valid, 372 SdHoareTripleChecker+Invalid, 136 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 117 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:10,773 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [66 Valid, 372 Invalid, 136 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 117 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 12:10:10,774 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 151 states. [2022-11-16 12:10:10,821 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 151 to 146. [2022-11-16 12:10:10,822 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 146 states, 114 states have (on average 1.280701754385965) internal successors, (146), 121 states have internal predecessors, (146), 16 states have call successors, (16), 12 states have call predecessors, (16), 15 states have return successors, (23), 17 states have call predecessors, (23), 16 states have call successors, (23) [2022-11-16 12:10:10,823 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 146 states to 146 states and 185 transitions. [2022-11-16 12:10:10,823 INFO L78 Accepts]: Start accepts. Automaton has 146 states and 185 transitions. Word has length 52 [2022-11-16 12:10:10,824 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:10,824 INFO L495 AbstractCegarLoop]: Abstraction has 146 states and 185 transitions. [2022-11-16 12:10:10,824 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:10,825 INFO L276 IsEmpty]: Start isEmpty. Operand 146 states and 185 transitions. [2022-11-16 12:10:10,827 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-16 12:10:10,827 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:10,827 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:10,827 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 12:10:10,828 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:10,828 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:10,828 INFO L85 PathProgramCache]: Analyzing trace with hash 2141595306, now seen corresponding path program 1 times [2022-11-16 12:10:10,829 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:10,829 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1242605034] [2022-11-16 12:10:10,829 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:10,829 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:10,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,918 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:10,919 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,937 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-16 12:10:10,940 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,978 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-16 12:10:10,979 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:10,981 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:10,981 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:10,981 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1242605034] [2022-11-16 12:10:10,981 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1242605034] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:10,982 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:10,982 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 12:10:10,982 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [421603034] [2022-11-16 12:10:10,982 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:10,983 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 12:10:10,983 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:10,983 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 12:10:10,984 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 12:10:10,984 INFO L87 Difference]: Start difference. First operand 146 states and 185 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:11,121 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:11,121 INFO L93 Difference]: Finished difference Result 294 states and 382 transitions. [2022-11-16 12:10:11,121 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 12:10:11,122 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-16 12:10:11,122 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:11,123 INFO L225 Difference]: With dead ends: 294 [2022-11-16 12:10:11,124 INFO L226 Difference]: Without dead ends: 156 [2022-11-16 12:10:11,124 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-16 12:10:11,125 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 65 mSDsluCounter, 204 mSDsCounter, 0 mSdLazyCounter, 89 mSolverCounterSat, 15 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 291 SdHoareTripleChecker+Invalid, 104 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 15 IncrementalHoareTripleChecker+Valid, 89 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:11,126 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 291 Invalid, 104 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [15 Valid, 89 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 12:10:11,127 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 156 states. [2022-11-16 12:10:11,143 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 156 to 148. [2022-11-16 12:10:11,144 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 148 states, 116 states have (on average 1.2758620689655173) internal successors, (148), 123 states have internal predecessors, (148), 16 states have call successors, (16), 12 states have call predecessors, (16), 15 states have return successors, (23), 17 states have call predecessors, (23), 16 states have call successors, (23) [2022-11-16 12:10:11,145 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 148 states to 148 states and 187 transitions. [2022-11-16 12:10:11,145 INFO L78 Accepts]: Start accepts. Automaton has 148 states and 187 transitions. Word has length 52 [2022-11-16 12:10:11,146 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:11,146 INFO L495 AbstractCegarLoop]: Abstraction has 148 states and 187 transitions. [2022-11-16 12:10:11,146 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:11,147 INFO L276 IsEmpty]: Start isEmpty. Operand 148 states and 187 transitions. [2022-11-16 12:10:11,147 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-16 12:10:11,147 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:11,148 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:11,148 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 12:10:11,148 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:11,148 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:11,149 INFO L85 PathProgramCache]: Analyzing trace with hash -1730670164, now seen corresponding path program 1 times [2022-11-16 12:10:11,149 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:11,149 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1517749848] [2022-11-16 12:10:11,149 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:11,150 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:11,166 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,245 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:11,247 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,253 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-16 12:10:11,256 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,271 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2022-11-16 12:10:11,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,274 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:11,274 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:11,275 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1517749848] [2022-11-16 12:10:11,275 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1517749848] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:11,275 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:11,275 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 12:10:11,275 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [28092739] [2022-11-16 12:10:11,276 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:11,276 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 12:10:11,276 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:11,277 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 12:10:11,277 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-16 12:10:11,277 INFO L87 Difference]: Start difference. First operand 148 states and 187 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:11,584 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:11,585 INFO L93 Difference]: Finished difference Result 428 states and 559 transitions. [2022-11-16 12:10:11,585 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-16 12:10:11,586 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2022-11-16 12:10:11,586 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:11,588 INFO L225 Difference]: With dead ends: 428 [2022-11-16 12:10:11,588 INFO L226 Difference]: Without dead ends: 288 [2022-11-16 12:10:11,589 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-16 12:10:11,590 INFO L413 NwaCegarLoop]: 136 mSDtfsCounter, 211 mSDsluCounter, 168 mSDsCounter, 0 mSdLazyCounter, 161 mSolverCounterSat, 59 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 218 SdHoareTripleChecker+Valid, 304 SdHoareTripleChecker+Invalid, 220 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 59 IncrementalHoareTripleChecker+Valid, 161 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:11,590 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [218 Valid, 304 Invalid, 220 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [59 Valid, 161 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 12:10:11,591 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 288 states. [2022-11-16 12:10:11,639 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 288 to 280. [2022-11-16 12:10:11,640 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 280 states, 216 states have (on average 1.25) internal successors, (270), 227 states have internal predecessors, (270), 34 states have call successors, (34), 28 states have call predecessors, (34), 29 states have return successors, (53), 34 states have call predecessors, (53), 34 states have call successors, (53) [2022-11-16 12:10:11,643 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 280 states to 280 states and 357 transitions. [2022-11-16 12:10:11,644 INFO L78 Accepts]: Start accepts. Automaton has 280 states and 357 transitions. Word has length 52 [2022-11-16 12:10:11,646 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:11,646 INFO L495 AbstractCegarLoop]: Abstraction has 280 states and 357 transitions. [2022-11-16 12:10:11,647 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-16 12:10:11,647 INFO L276 IsEmpty]: Start isEmpty. Operand 280 states and 357 transitions. [2022-11-16 12:10:11,651 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2022-11-16 12:10:11,652 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:11,652 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:11,652 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 12:10:11,652 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:11,653 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:11,653 INFO L85 PathProgramCache]: Analyzing trace with hash 742025993, now seen corresponding path program 1 times [2022-11-16 12:10:11,653 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:11,653 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [849768663] [2022-11-16 12:10:11,654 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:11,655 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:11,688 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,833 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-16 12:10:11,835 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,843 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2022-11-16 12:10:11,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,852 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-16 12:10:11,853 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 46 [2022-11-16 12:10:11,856 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:11,867 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 12:10:11,868 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:11,868 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [849768663] [2022-11-16 12:10:11,868 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [849768663] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:11,868 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:11,868 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-16 12:10:11,868 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [422142522] [2022-11-16 12:10:11,869 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:11,869 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-16 12:10:11,869 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:11,870 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-16 12:10:11,870 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-16 12:10:11,870 INFO L87 Difference]: Start difference. First operand 280 states and 357 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-11-16 12:10:12,205 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:12,206 INFO L93 Difference]: Finished difference Result 568 states and 737 transitions. [2022-11-16 12:10:12,206 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2022-11-16 12:10:12,206 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) Word has length 54 [2022-11-16 12:10:12,207 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:12,212 INFO L225 Difference]: With dead ends: 568 [2022-11-16 12:10:12,212 INFO L226 Difference]: Without dead ends: 296 [2022-11-16 12:10:12,214 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2022-11-16 12:10:12,215 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 108 mSDsluCounter, 334 mSDsCounter, 0 mSdLazyCounter, 203 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 114 SdHoareTripleChecker+Valid, 420 SdHoareTripleChecker+Invalid, 232 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 203 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:12,216 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [114 Valid, 420 Invalid, 232 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 203 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 12:10:12,218 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 296 states. [2022-11-16 12:10:12,257 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 296 to 276. [2022-11-16 12:10:12,258 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 276 states, 212 states have (on average 1.2169811320754718) internal successors, (258), 223 states have internal predecessors, (258), 34 states have call successors, (34), 28 states have call predecessors, (34), 29 states have return successors, (53), 34 states have call predecessors, (53), 34 states have call successors, (53) [2022-11-16 12:10:12,260 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 276 states to 276 states and 345 transitions. [2022-11-16 12:10:12,264 INFO L78 Accepts]: Start accepts. Automaton has 276 states and 345 transitions. Word has length 54 [2022-11-16 12:10:12,264 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:12,264 INFO L495 AbstractCegarLoop]: Abstraction has 276 states and 345 transitions. [2022-11-16 12:10:12,265 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-11-16 12:10:12,265 INFO L276 IsEmpty]: Start isEmpty. Operand 276 states and 345 transitions. [2022-11-16 12:10:12,266 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2022-11-16 12:10:12,266 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:12,267 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:12,267 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 12:10:12,267 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:12,267 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:12,268 INFO L85 PathProgramCache]: Analyzing trace with hash -731489466, now seen corresponding path program 1 times [2022-11-16 12:10:12,268 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:12,268 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1875832019] [2022-11-16 12:10:12,268 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:12,268 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:12,292 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:12,497 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-16 12:10:12,501 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:12,552 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-16 12:10:12,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:12,567 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-11-16 12:10:12,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:12,586 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2022-11-16 12:10:12,587 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:12,589 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-16 12:10:12,589 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:12,589 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1875832019] [2022-11-16 12:10:12,589 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1875832019] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:12,590 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:12,590 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-11-16 12:10:12,590 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1522883621] [2022-11-16 12:10:12,590 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:12,591 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-11-16 12:10:12,591 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:12,591 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-11-16 12:10:12,592 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=72, Unknown=0, NotChecked=0, Total=90 [2022-11-16 12:10:12,592 INFO L87 Difference]: Start difference. First operand 276 states and 345 transitions. Second operand has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-16 12:10:13,572 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:13,572 INFO L93 Difference]: Finished difference Result 873 states and 1145 transitions. [2022-11-16 12:10:13,573 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-16 12:10:13,573 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) Word has length 56 [2022-11-16 12:10:13,574 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:13,579 INFO L225 Difference]: With dead ends: 873 [2022-11-16 12:10:13,579 INFO L226 Difference]: Without dead ends: 656 [2022-11-16 12:10:13,581 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 43 GetRequests, 10 SyntacticMatches, 1 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 262 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=215, Invalid=907, Unknown=0, NotChecked=0, Total=1122 [2022-11-16 12:10:13,583 INFO L413 NwaCegarLoop]: 129 mSDtfsCounter, 476 mSDsluCounter, 687 mSDsCounter, 0 mSdLazyCounter, 767 mSolverCounterSat, 171 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 483 SdHoareTripleChecker+Valid, 816 SdHoareTripleChecker+Invalid, 938 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 171 IncrementalHoareTripleChecker+Valid, 767 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:13,584 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [483 Valid, 816 Invalid, 938 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [171 Valid, 767 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-16 12:10:13,585 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 656 states. [2022-11-16 12:10:13,655 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 656 to 533. [2022-11-16 12:10:13,657 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 533 states, 410 states have (on average 1.2146341463414634) internal successors, (498), 434 states have internal predecessors, (498), 65 states have call successors, (65), 49 states have call predecessors, (65), 57 states have return successors, (104), 67 states have call predecessors, (104), 65 states have call successors, (104) [2022-11-16 12:10:13,662 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 533 states to 533 states and 667 transitions. [2022-11-16 12:10:13,662 INFO L78 Accepts]: Start accepts. Automaton has 533 states and 667 transitions. Word has length 56 [2022-11-16 12:10:13,662 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:13,663 INFO L495 AbstractCegarLoop]: Abstraction has 533 states and 667 transitions. [2022-11-16 12:10:13,663 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-16 12:10:13,663 INFO L276 IsEmpty]: Start isEmpty. Operand 533 states and 667 transitions. [2022-11-16 12:10:13,664 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2022-11-16 12:10:13,664 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:13,665 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:13,665 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-16 12:10:13,665 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:13,666 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:13,666 INFO L85 PathProgramCache]: Analyzing trace with hash -981985599, now seen corresponding path program 1 times [2022-11-16 12:10:13,666 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:13,666 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1282181155] [2022-11-16 12:10:13,666 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:13,667 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:13,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,860 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-16 12:10:13,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,879 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-16 12:10:13,884 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,916 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:13,917 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 12:10:13,939 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,952 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-11-16 12:10:13,954 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,973 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-11-16 12:10:13,976 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,978 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 12:10:13,979 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,980 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2022-11-16 12:10:13,982 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:13,985 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 18 proven. 9 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-16 12:10:13,986 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:13,986 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1282181155] [2022-11-16 12:10:13,986 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1282181155] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 12:10:13,986 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [733386324] [2022-11-16 12:10:13,986 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:13,987 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 12:10:13,987 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 12:10:13,990 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 12:10:14,010 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 12:10:14,119 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:14,122 INFO L263 TraceCheckSpWp]: Trace formula consists of 472 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-16 12:10:14,129 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 12:10:14,349 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 25 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 12:10:14,349 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 12:10:14,570 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 19 proven. 8 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-16 12:10:14,571 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [733386324] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 12:10:14,571 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 12:10:14,571 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 6, 6] total 16 [2022-11-16 12:10:14,571 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2046315445] [2022-11-16 12:10:14,571 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 12:10:14,572 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 16 states [2022-11-16 12:10:14,572 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:14,572 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 16 interpolants. [2022-11-16 12:10:14,573 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=38, Invalid=202, Unknown=0, NotChecked=0, Total=240 [2022-11-16 12:10:14,573 INFO L87 Difference]: Start difference. First operand 533 states and 667 transitions. Second operand has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2022-11-16 12:10:15,812 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:15,812 INFO L93 Difference]: Finished difference Result 1171 states and 1508 transitions. [2022-11-16 12:10:15,813 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2022-11-16 12:10:15,813 INFO L78 Accepts]: Start accepts. Automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) Word has length 96 [2022-11-16 12:10:15,813 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:15,817 INFO L225 Difference]: With dead ends: 1171 [2022-11-16 12:10:15,817 INFO L226 Difference]: Without dead ends: 695 [2022-11-16 12:10:15,820 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 263 GetRequests, 215 SyntacticMatches, 4 SemanticMatches, 44 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 508 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=361, Invalid=1709, Unknown=0, NotChecked=0, Total=2070 [2022-11-16 12:10:15,820 INFO L413 NwaCegarLoop]: 181 mSDtfsCounter, 440 mSDsluCounter, 1114 mSDsCounter, 0 mSdLazyCounter, 921 mSolverCounterSat, 189 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 441 SdHoareTripleChecker+Valid, 1295 SdHoareTripleChecker+Invalid, 1110 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 189 IncrementalHoareTripleChecker+Valid, 921 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.7s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:15,821 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [441 Valid, 1295 Invalid, 1110 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [189 Valid, 921 Invalid, 0 Unknown, 0 Unchecked, 0.7s Time] [2022-11-16 12:10:15,822 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 695 states. [2022-11-16 12:10:15,882 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 695 to 598. [2022-11-16 12:10:15,883 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 598 states, 454 states have (on average 1.2026431718061674) internal successors, (546), 486 states have internal predecessors, (546), 75 states have call successors, (75), 63 states have call predecessors, (75), 68 states have return successors, (100), 70 states have call predecessors, (100), 75 states have call successors, (100) [2022-11-16 12:10:15,887 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 598 states to 598 states and 721 transitions. [2022-11-16 12:10:15,887 INFO L78 Accepts]: Start accepts. Automaton has 598 states and 721 transitions. Word has length 96 [2022-11-16 12:10:15,888 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:15,888 INFO L495 AbstractCegarLoop]: Abstraction has 598 states and 721 transitions. [2022-11-16 12:10:15,888 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2022-11-16 12:10:15,888 INFO L276 IsEmpty]: Start isEmpty. Operand 598 states and 721 transitions. [2022-11-16 12:10:15,891 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 169 [2022-11-16 12:10:15,891 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:15,892 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:15,899 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-16 12:10:16,097 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-16 12:10:16,098 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:16,098 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:16,098 INFO L85 PathProgramCache]: Analyzing trace with hash -1684606529, now seen corresponding path program 1 times [2022-11-16 12:10:16,099 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:16,099 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1021655198] [2022-11-16 12:10:16,099 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:16,099 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:16,127 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,250 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-16 12:10:16,252 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,261 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-16 12:10:16,265 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,271 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:16,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,278 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 12:10:16,280 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,283 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-11-16 12:10:16,287 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,293 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:16,295 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,296 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-16 12:10:16,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,301 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 12:10:16,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,303 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2022-11-16 12:10:16,308 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,434 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:16,435 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,437 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 135 [2022-11-16 12:10:16,437 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,439 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 144 [2022-11-16 12:10:16,440 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,443 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 160 [2022-11-16 12:10:16,443 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:16,445 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 81 proven. 0 refuted. 0 times theorem prover too weak. 109 trivial. 0 not checked. [2022-11-16 12:10:16,445 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:16,445 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1021655198] [2022-11-16 12:10:16,446 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1021655198] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:16,446 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 12:10:16,446 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-11-16 12:10:16,446 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1138567624] [2022-11-16 12:10:16,446 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:16,447 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-11-16 12:10:16,447 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:16,448 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-11-16 12:10:16,448 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=69, Unknown=0, NotChecked=0, Total=90 [2022-11-16 12:10:16,448 INFO L87 Difference]: Start difference. First operand 598 states and 721 transitions. Second operand has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) [2022-11-16 12:10:17,376 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:17,377 INFO L93 Difference]: Finished difference Result 1713 states and 2093 transitions. [2022-11-16 12:10:17,377 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-11-16 12:10:17,377 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) Word has length 168 [2022-11-16 12:10:17,378 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:17,384 INFO L225 Difference]: With dead ends: 1713 [2022-11-16 12:10:17,384 INFO L226 Difference]: Without dead ends: 1123 [2022-11-16 12:10:17,386 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 62 GetRequests, 36 SyntacticMatches, 0 SemanticMatches, 26 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 150 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=178, Invalid=578, Unknown=0, NotChecked=0, Total=756 [2022-11-16 12:10:17,387 INFO L413 NwaCegarLoop]: 175 mSDtfsCounter, 497 mSDsluCounter, 519 mSDsCounter, 0 mSdLazyCounter, 548 mSolverCounterSat, 149 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 501 SdHoareTripleChecker+Valid, 694 SdHoareTripleChecker+Invalid, 697 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 149 IncrementalHoareTripleChecker+Valid, 548 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:17,387 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [501 Valid, 694 Invalid, 697 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [149 Valid, 548 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-16 12:10:17,390 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1123 states. [2022-11-16 12:10:17,518 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1123 to 1121. [2022-11-16 12:10:17,520 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1121 states, 849 states have (on average 1.171967020023557) internal successors, (995), 904 states have internal predecessors, (995), 143 states have call successors, (143), 122 states have call predecessors, (143), 128 states have return successors, (186), 130 states have call predecessors, (186), 143 states have call successors, (186) [2022-11-16 12:10:17,526 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1121 states to 1121 states and 1324 transitions. [2022-11-16 12:10:17,526 INFO L78 Accepts]: Start accepts. Automaton has 1121 states and 1324 transitions. Word has length 168 [2022-11-16 12:10:17,527 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:17,527 INFO L495 AbstractCegarLoop]: Abstraction has 1121 states and 1324 transitions. [2022-11-16 12:10:17,527 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 8.7) internal successors, (87), 7 states have internal predecessors, (87), 3 states have call successors, (10), 5 states have call predecessors, (10), 2 states have return successors, (10), 3 states have call predecessors, (10), 3 states have call successors, (10) [2022-11-16 12:10:17,527 INFO L276 IsEmpty]: Start isEmpty. Operand 1121 states and 1324 transitions. [2022-11-16 12:10:17,531 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 173 [2022-11-16 12:10:17,531 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:17,532 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:17,532 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2022-11-16 12:10:17,532 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:17,533 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:17,533 INFO L85 PathProgramCache]: Analyzing trace with hash 734259323, now seen corresponding path program 1 times [2022-11-16 12:10:17,533 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:17,533 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1574976519] [2022-11-16 12:10:17,533 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:17,534 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:17,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,665 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-16 12:10:17,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,671 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-11-16 12:10:17,672 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,682 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-11-16 12:10:17,686 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,691 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:17,692 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,698 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 12:10:17,700 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,702 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-11-16 12:10:17,709 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,780 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:17,781 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,782 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-16 12:10:17,783 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,785 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 12:10:17,785 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,786 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-11-16 12:10:17,790 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,793 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:17,794 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 139 [2022-11-16 12:10:17,796 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,797 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 148 [2022-11-16 12:10:17,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,801 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 164 [2022-11-16 12:10:17,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,805 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 87 proven. 10 refuted. 0 times theorem prover too weak. 93 trivial. 0 not checked. [2022-11-16 12:10:17,805 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:17,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1574976519] [2022-11-16 12:10:17,805 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1574976519] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 12:10:17,806 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1133164193] [2022-11-16 12:10:17,806 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:17,806 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 12:10:17,806 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 12:10:17,807 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 12:10:17,835 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 12:10:17,971 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:17,974 INFO L263 TraceCheckSpWp]: Trace formula consists of 677 conjuncts, 7 conjunts are in the unsatisfiable core [2022-11-16 12:10:17,979 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 12:10:18,160 INFO L134 CoverageAnalysis]: Checked inductivity of 190 backedges. 131 proven. 0 refuted. 0 times theorem prover too weak. 59 trivial. 0 not checked. [2022-11-16 12:10:18,161 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 12:10:18,161 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1133164193] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 12:10:18,161 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 12:10:18,161 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 15 [2022-11-16 12:10:18,161 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [824396036] [2022-11-16 12:10:18,162 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 12:10:18,162 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 12:10:18,162 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:18,163 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 12:10:18,163 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=37, Invalid=173, Unknown=0, NotChecked=0, Total=210 [2022-11-16 12:10:18,163 INFO L87 Difference]: Start difference. First operand 1121 states and 1324 transitions. Second operand has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) [2022-11-16 12:10:18,410 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:18,410 INFO L93 Difference]: Finished difference Result 2058 states and 2439 transitions. [2022-11-16 12:10:18,411 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-16 12:10:18,411 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) Word has length 172 [2022-11-16 12:10:18,411 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:18,416 INFO L225 Difference]: With dead ends: 2058 [2022-11-16 12:10:18,416 INFO L226 Difference]: Without dead ends: 1043 [2022-11-16 12:10:18,421 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 208 GetRequests, 193 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 29 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=52, Invalid=220, Unknown=0, NotChecked=0, Total=272 [2022-11-16 12:10:18,422 INFO L413 NwaCegarLoop]: 164 mSDtfsCounter, 65 mSDsluCounter, 415 mSDsCounter, 0 mSdLazyCounter, 75 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 579 SdHoareTripleChecker+Invalid, 78 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 75 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:18,422 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 579 Invalid, 78 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 75 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 12:10:18,424 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1043 states. [2022-11-16 12:10:18,529 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1043 to 1027. [2022-11-16 12:10:18,531 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1027 states, 784 states have (on average 1.1658163265306123) internal successors, (914), 830 states have internal predecessors, (914), 128 states have call successors, (128), 111 states have call predecessors, (128), 114 states have return successors, (164), 116 states have call predecessors, (164), 128 states have call successors, (164) [2022-11-16 12:10:18,536 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1027 states to 1027 states and 1206 transitions. [2022-11-16 12:10:18,537 INFO L78 Accepts]: Start accepts. Automaton has 1027 states and 1206 transitions. Word has length 172 [2022-11-16 12:10:18,538 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:18,538 INFO L495 AbstractCegarLoop]: Abstraction has 1027 states and 1206 transitions. [2022-11-16 12:10:18,538 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (12), 3 states have call predecessors, (12), 3 states have call successors, (12) [2022-11-16 12:10:18,538 INFO L276 IsEmpty]: Start isEmpty. Operand 1027 states and 1206 transitions. [2022-11-16 12:10:18,542 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 177 [2022-11-16 12:10:18,542 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 12:10:18,543 INFO L195 NwaCegarLoop]: trace histogram [5, 5, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:18,549 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-11-16 12:10:18,748 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-16 12:10:18,749 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 12:10:18,749 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 12:10:18,749 INFO L85 PathProgramCache]: Analyzing trace with hash 1208270879, now seen corresponding path program 1 times [2022-11-16 12:10:18,749 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-16 12:10:18,749 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1117334844] [2022-11-16 12:10:18,749 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:18,749 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 12:10:18,781 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:18,981 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-11-16 12:10:18,982 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:18,991 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-11-16 12:10:18,995 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,027 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:19,028 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,035 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-16 12:10:19,037 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,041 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-11-16 12:10:19,044 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,129 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:19,130 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,132 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-16 12:10:19,135 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,138 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-16 12:10:19,139 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,150 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 97 [2022-11-16 12:10:19,151 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,152 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-11-16 12:10:19,155 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,158 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2022-11-16 12:10:19,159 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,161 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 132 [2022-11-16 12:10:19,161 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,163 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 143 [2022-11-16 12:10:19,163 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,164 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 152 [2022-11-16 12:10:19,166 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,168 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 168 [2022-11-16 12:10:19,169 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,171 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 93 proven. 28 refuted. 0 times theorem prover too weak. 73 trivial. 0 not checked. [2022-11-16 12:10:19,171 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-16 12:10:19,171 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1117334844] [2022-11-16 12:10:19,171 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1117334844] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 12:10:19,171 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1214420790] [2022-11-16 12:10:19,172 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 12:10:19,172 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 12:10:19,172 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 [2022-11-16 12:10:19,173 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 12:10:19,198 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 12:10:19,332 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 12:10:19,335 INFO L263 TraceCheckSpWp]: Trace formula consists of 684 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-16 12:10:19,339 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 12:10:19,624 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 142 proven. 4 refuted. 0 times theorem prover too weak. 48 trivial. 0 not checked. [2022-11-16 12:10:19,624 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 12:10:20,219 INFO L134 CoverageAnalysis]: Checked inductivity of 194 backedges. 82 proven. 42 refuted. 0 times theorem prover too weak. 70 trivial. 0 not checked. [2022-11-16 12:10:20,219 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1214420790] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 12:10:20,220 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 12:10:20,220 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 10, 11] total 26 [2022-11-16 12:10:20,220 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [751077346] [2022-11-16 12:10:20,220 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 12:10:20,221 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 26 states [2022-11-16 12:10:20,221 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-16 12:10:20,222 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 26 interpolants. [2022-11-16 12:10:20,222 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=123, Invalid=527, Unknown=0, NotChecked=0, Total=650 [2022-11-16 12:10:20,223 INFO L87 Difference]: Start difference. First operand 1027 states and 1206 transitions. Second operand has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) [2022-11-16 12:10:21,953 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 12:10:21,953 INFO L93 Difference]: Finished difference Result 2162 states and 2608 transitions. [2022-11-16 12:10:21,954 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-11-16 12:10:21,954 INFO L78 Accepts]: Start accepts. Automaton has has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) Word has length 176 [2022-11-16 12:10:21,955 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 12:10:21,956 INFO L225 Difference]: With dead ends: 2162 [2022-11-16 12:10:21,956 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 12:10:21,961 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 428 GetRequests, 373 SyntacticMatches, 5 SemanticMatches, 50 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 530 ImplicationChecksByTransitivity, 0.9s TimeCoverageRelationStatistics Valid=549, Invalid=2103, Unknown=0, NotChecked=0, Total=2652 [2022-11-16 12:10:21,962 INFO L413 NwaCegarLoop]: 42 mSDtfsCounter, 626 mSDsluCounter, 443 mSDsCounter, 0 mSdLazyCounter, 1520 mSolverCounterSat, 200 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 629 SdHoareTripleChecker+Valid, 485 SdHoareTripleChecker+Invalid, 1720 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 200 IncrementalHoareTripleChecker+Valid, 1520 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-11-16 12:10:21,963 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [629 Valid, 485 Invalid, 1720 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [200 Valid, 1520 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-11-16 12:10:21,964 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 12:10:21,964 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 12:10:21,964 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 12:10:21,964 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 12:10:21,965 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 176 [2022-11-16 12:10:21,965 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 12:10:21,965 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 12:10:21,966 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 26 states, 26 states have (on average 8.115384615384615) internal successors, (211), 22 states have internal predecessors, (211), 10 states have call successors, (34), 9 states have call predecessors, (34), 9 states have return successors, (31), 9 states have call predecessors, (31), 10 states have call successors, (31) [2022-11-16 12:10:21,966 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 12:10:21,966 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 12:10:21,969 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 12:10:21,986 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 12:10:22,176 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable12 [2022-11-16 12:10:22,178 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 12:10:37,863 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 713 719) no Hoare annotation was computed. [2022-11-16 12:10:37,864 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 713 719) the Hoare annotation is: true [2022-11-16 12:10:37,864 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 612 623) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 0))) (.cse6 (not (<= 1 |old(~methaneLevelCritical~0)|))) (.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse5 (not (<= 1 ~pumpRunning~0))) (.cse3 (not (<= ~waterLevel~0 2))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 (not (= 2 ~waterLevel~0)) .cse2 .cse5 .cse4) (or .cse2 (not (<= 2 ~waterLevel~0)) .cse5 .cse6 .cse3 .cse4) (or .cse1 .cse2 .cse6 .cse3 .cse4) (or .cse0 .cse2 .cse5 .cse3 .cse4 (not (<= 1 ~switchedOnBeforeTS~0))))) [2022-11-16 12:10:37,864 INFO L899 garLoopResultBuilder]: For program point L616-1(lines 612 623) no Hoare annotation was computed. [2022-11-16 12:10:37,864 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 612 623) no Hoare annotation was computed. [2022-11-16 12:10:37,865 INFO L895 garLoopResultBuilder]: At program point L766(line 766) the Hoare annotation is: (let ((.cse9 (= ~pumpRunning~0 0))) (let ((.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (and .cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (not (<= 1 |old(~pumpRunning~0)|))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse4 (= 0 ~systemActive~0)) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse4) (or .cse1 .cse2 .cse3 .cse7 .cse4) (or .cse1 .cse6 .cse4 .cse8 (and .cse9 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse5 .cse3 .cse4 .cse10) (or .cse0 .cse1 .cse2 .cse6 .cse4) (or .cse5 (not (< 1 |old(~waterLevel~0)|)) .cse3 .cse4 .cse8) (or .cse5 .cse6 .cse4 .cse8 .cse10)))) [2022-11-16 12:10:37,865 INFO L895 garLoopResultBuilder]: At program point L766-1(lines 747 771) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse21 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse22 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse23 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse24 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse25 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse14 (= ~pumpRunning~0 0)) (.cse26 (<= 1 ~methaneLevelCritical~0)) (.cse15 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse27 (<= ~waterLevel~0 1)) (.cse28 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse16 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0)) (.cse18 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse11 (and .cse14 .cse26 .cse15 .cse27 .cse28 .cse16 .cse17 (not .cse4) .cse18)) (.cse13 (not (<= |old(~waterLevel~0)| 1))) (.cse20 (= ~waterLevel~0 1)) (.cse19 (not (< 1 |old(~waterLevel~0)|))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (and .cse21 .cse22 .cse15 .cse27 .cse28 .cse23 .cse24 .cse16 .cse25)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (and .cse14 .cse9)) (.cse12 (not .cse26)) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (<= 1 ~pumpRunning~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse3 (and .cse8 .cse9) .cse4 .cse10) (or .cse0 .cse11 .cse1 .cse12 .cse4 .cse5) (or .cse13 (and .cse14 .cse15 .cse9 .cse16 .cse17 .cse18) .cse11 .cse1 .cse12 .cse4 .cse5) (or .cse1 .cse19 .cse12 (and .cse14 .cse15 .cse20 .cse16 .cse17 .cse18) .cse4 .cse10) (or .cse13 .cse6 .cse7 .cse3 .cse4) (or (and .cse21 .cse22 .cse15 .cse23 .cse24 .cse20 .cse16 .cse25) .cse1 .cse19 .cse3 .cse4 .cse10) (or .cse1 .cse2 .cse3 (and .cse21 .cse22 .cse15 .cse23 .cse24 .cse9 .cse16 .cse25) .cse4 .cse10 .cse5) (or .cse6 .cse7 .cse12 .cse4 .cse10 (and .cse8 (= 2 ~waterLevel~0) .cse9))))) [2022-11-16 12:10:37,866 INFO L895 garLoopResultBuilder]: At program point L795(lines 788 798) the Hoare annotation is: (let ((.cse9 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse12 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse22 (<= 1 ~pumpRunning~0)) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse21 (<= 1 ~methaneLevelCritical~0)) (.cse8 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse23 (<= ~waterLevel~0 1)) (.cse24 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse11 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0))) (let ((.cse6 (not (< 1 |old(~waterLevel~0)|))) (.cse10 (= ~waterLevel~0 1)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse16 (not (<= 2 |old(~waterLevel~0)|))) (.cse18 (and .cse22 .cse7 .cse21 .cse8 .cse23 .cse24 .cse11 .cse17 (not .cse4))) (.cse13 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (and .cse22 .cse7 .cse8 .cse23 .cse24 .cse9 .cse11 .cse12)) (.cse19 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse20 (not (<= |old(~waterLevel~0)| 1))) (.cse14 (not (= |old(~pumpRunning~0)| 0))) (.cse15 (not .cse21))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse1 .cse6 .cse2 .cse4 (and .cse7 .cse8 .cse9 .cse10 .cse11 .cse12) .cse13) (or .cse14 .cse15 .cse4 .cse13 .cse16) (or .cse1 .cse6 .cse15 .cse4 .cse13 (and .cse7 .cse8 .cse10 .cse11 .cse17)) (or .cse0 .cse1 .cse18 .cse15 .cse4 .cse5) (or .cse14 .cse2 .cse4 .cse13 .cse16) (or (and .cse7 .cse8 .cse19 .cse11 .cse17) .cse1 .cse18 .cse15 .cse4 .cse13 .cse5) (or .cse20 .cse1 .cse2 .cse3 .cse4 (and .cse7 .cse8 .cse9 .cse19 .cse11 .cse12) .cse5) (or .cse20 .cse14 .cse2 .cse4) (or .cse20 .cse14 .cse15 .cse4)))) [2022-11-16 12:10:37,866 INFO L899 garLoopResultBuilder]: For program point L700-1(lines 700 706) no Hoare annotation was computed. [2022-11-16 12:10:37,866 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 686 712) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L895 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse11 (and .cse15 .cse13 .cse14)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (and (<= 1 ~pumpRunning~0) .cse15 .cse13 (< 1 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (and (= ~pumpRunning~0 0) .cse13 .cse14)) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse2 .cse4) (or .cse6 .cse8 .cse9 .cse10 .cse4) (or .cse0 .cse2 .cse4 .cse5 .cse11 .cse12) (or .cse6 .cse7 .cse8 .cse9 .cse4) (or .cse7 .cse0 .cse9 .cse4 .cse11 .cse12) (or .cse0 .cse1 .cse3 .cse9 .cse4 .cse5) (or .cse6 .cse8 .cse2 .cse10 .cse4)))) [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L693(lines 693 699) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L181-1(line 181) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L693-2(lines 689 711) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L755(lines 755 763) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L751(lines 751 768) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L198(lines 198 208) no Hoare annotation was computed. [2022-11-16 12:10:37,867 INFO L899 garLoopResultBuilder]: For program point L194(lines 194 211) no Hoare annotation was computed. [2022-11-16 12:10:37,868 INFO L895 garLoopResultBuilder]: At program point L194-1(lines 186 214) the Hoare annotation is: (let ((.cse12 (= 0 ~systemActive~0))) (let ((.cse26 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse27 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse28 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse29 (<= 0 |timeShift_isMethaneAlarm_#res#1|)) (.cse25 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse19 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse32 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse30 (<= ~waterLevel~0 1)) (.cse31 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse6 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| ~waterLevel~0)) (.cse8 (<= 1 ~switchedOnBeforeTS~0)) (.cse9 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse10 (not .cse12)) (.cse11 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse14 (not (= |old(~waterLevel~0)| 1))) (.cse15 (and .cse3 .cse4 .cse32 .cse5 .cse30 .cse31 .cse6 .cse8 .cse9 .cse10 .cse11)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse7 (= ~waterLevel~0 1)) (.cse20 (not (= |old(~pumpRunning~0)| 0))) (.cse24 (and .cse25 .cse3 .cse4 .cse6 .cse19 .cse10)) (.cse2 (not .cse32)) (.cse21 (<= 1 ~pumpRunning~0)) (.cse17 (and .cse25 .cse4 .cse26 .cse5 .cse30 .cse31 .cse27 .cse28 .cse6 .cse8 .cse29 .cse10)) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse18 (not (= ~methaneLevelCritical~0 0))) (.cse13 (not (<= |old(~waterLevel~0)| 2))) (.cse16 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5 .cse6 .cse7 .cse8 .cse9 .cse10 .cse11) .cse12 .cse13) (or .cse14 .cse0 .cse2 .cse15 .cse12 .cse16) (or .cse17 .cse14 .cse0 .cse18 .cse12 .cse16) (or (and .cse3 .cse4 .cse5 .cse6 .cse19 .cse8 .cse9 .cse10 .cse11) .cse0 .cse2 .cse15 .cse12 .cse13 .cse16) (let ((.cse22 (= 2 |timeShift_getWaterLevel_#res#1|)) (.cse23 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| 2))) (or .cse20 (and .cse21 .cse22 .cse23 .cse19) (and .cse3 .cse22 .cse23 .cse19) .cse18 .cse12 .cse13 (not (<= 2 |old(~waterLevel~0)|)))) (or (not (<= |old(~waterLevel~0)| 1)) .cse20 .cse24 .cse18 .cse12) (or .cse0 .cse1 .cse18 .cse12 .cse13 (and .cse25 .cse4 .cse26 .cse5 .cse27 .cse28 .cse6 .cse7 .cse8 .cse29 .cse10)) (or .cse20 .cse24 .cse2 .cse12 .cse13 (and .cse21 .cse4 (<= 2 ~waterLevel~0) .cse6 .cse19)) (or .cse17 .cse0 .cse18 .cse12 .cse13 (and .cse25 .cse4 .cse26 .cse5 .cse27 .cse28 .cse6 .cse19 .cse8 .cse29 .cse10) .cse16))))) [2022-11-16 12:10:37,868 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-11-16 12:10:37,869 INFO L895 garLoopResultBuilder]: At program point L661(lines 656 664) the Hoare annotation is: (let ((.cse23 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse8 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse10 (= 0 ~systemActive~0)) (.cse9 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|)) (.cse29 (<= 1 ~methaneLevelCritical~0)) (.cse15 (<= 1 ~pumpRunning~0)) (.cse19 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse28 (= ~methaneLevelCritical~0 0)) (.cse20 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse5 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse30 (<= ~waterLevel~0 1)) (.cse31 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse21 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse22 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse7 (<= 1 ~switchedOnBeforeTS~0)) (.cse24 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse18 (and .cse15 .cse19 .cse4 .cse28 .cse20 .cse5 .cse30 .cse31 .cse21 .cse22 .cse7 .cse24)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse6 (= ~waterLevel~0 1)) (.cse16 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not .cse29)) (.cse25 (and .cse3 .cse4 .cse29 .cse5 .cse30 .cse31 .cse7 .cse8 (not .cse10) .cse9)) (.cse17 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse12 (not (= |old(~pumpRunning~0)| 0))) (.cse27 (= 2 ~waterLevel~0)) (.cse26 (and .cse3 .cse4 .cse23)) (.cse13 (not .cse28)) (.cse11 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5 .cse6 .cse7 .cse8 .cse9) .cse10 .cse11) (let ((.cse14 (= 2 |timeShift_getWaterLevel_#res#1|))) (or .cse12 .cse13 .cse10 .cse11 (and .cse3 .cse14) (and .cse15 .cse14) (not (<= 2 |old(~waterLevel~0)|)))) (or .cse16 .cse0 .cse13 .cse10 .cse17 .cse18) (or .cse0 .cse13 .cse10 .cse11 (and .cse19 .cse4 .cse20 .cse5 .cse21 .cse22 .cse23 .cse7 .cse24) .cse17 .cse18) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and .cse3 .cse4 .cse5 .cse23 .cse7 .cse8 .cse9) .cse2 .cse10 .cse25 .cse17) (or .cse12 .cse26 .cse2 .cse10 .cse11 (and .cse15 .cse4 .cse27 .cse23)) (or .cse0 .cse1 .cse13 (and .cse19 .cse4 .cse20 .cse5 .cse21 .cse22 .cse6 .cse7 .cse24) .cse10 .cse11) (or .cse16 .cse0 .cse2 .cse10 .cse25 .cse17) (or .cse12 (and .cse27 .cse23) .cse26 .cse13 .cse10 .cse11)))) [2022-11-16 12:10:37,869 INFO L895 garLoopResultBuilder]: At program point L785(lines 780 787) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse15 (<= 1 ~methaneLevelCritical~0)) (.cse11 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse12 (<= 1 ~switchedOnBeforeTS~0)) (.cse13 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse2 (= 0 ~systemActive~0)) (.cse14 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|))) (let ((.cse7 (and .cse10 .cse15 .cse11 (<= ~waterLevel~0 1) (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|) .cse12 .cse13 (not .cse2) .cse14)) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse9 (not (<= |old(~waterLevel~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not .cse15))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2)) .cse2) (or .cse3 .cse4 .cse2 .cse5 .cse6) (or (not (= |old(~waterLevel~0)| 1)) .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse9 (and .cse10 .cse11 (= |old(~waterLevel~0)| ~waterLevel~0) .cse12 .cse13 .cse14) .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse3 .cse1 .cse2 .cse5 .cse6) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) .cse4 (and .cse10 .cse11 (= ~waterLevel~0 1) .cse12 .cse13 .cse14) .cse2 .cse5) (or .cse9 .cse3 .cse1 .cse2) (or .cse0 .cse1 .cse2 .cse5 .cse8) (or .cse9 .cse3 .cse4 .cse2)))) [2022-11-16 12:10:37,869 INFO L899 garLoopResultBuilder]: For program point L199(lines 199 205) no Hoare annotation was computed. [2022-11-16 12:10:37,870 INFO L895 garLoopResultBuilder]: At program point L761(line 761) the Hoare annotation is: (let ((.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse12 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse13 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse14 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse15 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse16 (<= 1 ~switchedOnBeforeTS~0)) (.cse17 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse10 (not (< 1 |old(~waterLevel~0)|))) (.cse9 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (and .cse11 .cse12 .cse13 (<= ~waterLevel~0 1) (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|) .cse14 .cse15 .cse16 .cse17)) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= 0 ~systemActive~0)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse8) (or .cse9 .cse0 .cse6 .cse3 .cse4) (or .cse5 .cse2 .cse3 .cse7 .cse8) (or .cse0 .cse10 .cse6 .cse3 .cse7) (or (and .cse11 .cse12 .cse13 .cse14 .cse15 (= ~waterLevel~0 1) .cse16 .cse17) .cse0 .cse10 .cse2 .cse3 .cse7) (or .cse9 .cse5 .cse2 .cse3) (or .cse9 .cse5 .cse6 .cse3) (or .cse0 .cse1 .cse2 (and .cse11 .cse12 .cse13 .cse14 .cse15 (= |old(~waterLevel~0)| ~waterLevel~0) .cse16 .cse17) .cse3 .cse7 .cse4)))) [2022-11-16 12:10:37,870 INFO L895 garLoopResultBuilder]: At program point L183(lines 176 185) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 0)) (.cse14 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse17 (<= 1 ~switchedOnBeforeTS~0))) (let ((.cse5 (and .cse14 .cse16 .cse17)) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse12 (and (<= 1 ~pumpRunning~0) .cse14 .cse16 .cse17)) (.cse6 (not (<= 1 |old(~pumpRunning~0)|))) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (and .cse15 .cse16)) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (and .cse14 .cse15 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse11 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse6 .cse7 .cse4 .cse8) (or .cse0 .cse5 .cse6 .cse3 .cse4 .cse8) (or .cse1 .cse9 .cse7 .cse4 .cse10 .cse11) (or .cse12 .cse6 .cse3 .cse13 .cse4) (or .cse12 .cse6 .cse7 .cse13 .cse4) (or .cse0 .cse1 .cse2 .cse7 .cse4) (or .cse1 .cse9 .cse3 .cse4 .cse10 .cse11)))) [2022-11-16 12:10:37,870 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2)) .cse2) (or .cse3 .cse4 .cse2 .cse5 .cse6) (or .cse7 .cse0 .cse4 .cse2 .cse8) (or .cse3 .cse1 .cse2 .cse5 .cse6) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) .cse4 .cse2 .cse5) (or .cse7 .cse3 .cse1 .cse2) (or .cse0 .cse1 .cse2 .cse5 .cse8) (or .cse7 .cse3 .cse4 .cse2))) [2022-11-16 12:10:37,871 INFO L895 garLoopResultBuilder]: At program point L629(lines 624 632) the Hoare annotation is: (let ((.cse15 (<= 1 ~methaneLevelCritical~0)) (.cse4 (= 0 ~systemActive~0)) (.cse17 (<= 1 ~pumpRunning~0)) (.cse16 (= ~methaneLevelCritical~0 0)) (.cse20 (<= ~waterLevel~0 1)) (.cse21 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse18 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse19 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse22 (<= 1 ~switchedOnBeforeTS~0))) (let ((.cse10 (not (< 1 |old(~waterLevel~0)|))) (.cse11 (and .cse18 .cse19 (= ~waterLevel~0 1) .cse22)) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse13 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (and .cse18 .cse19 (= |old(~waterLevel~0)| ~waterLevel~0) .cse22)) (.cse9 (and .cse17 .cse18 .cse16 .cse19 .cse20 .cse21 .cse22)) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (and .cse17 .cse18 .cse15 .cse19 .cse20 .cse21 .cse22 (not .cse4))) (.cse6 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not .cse16)) (.cse14 (not (<= |old(~waterLevel~0)| 1))) (.cse12 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not .cse15))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (or .cse7 .cse1 .cse8 .cse9 .cse4 .cse6) (or .cse1 .cse10 .cse8 .cse11 .cse4 .cse5) (or .cse12 .cse3 .cse4 .cse5 .cse13) (or .cse1 .cse10 .cse3 .cse11 .cse4 .cse5) (or .cse12 .cse8 .cse4 .cse5 .cse13) (or .cse14 .cse0 .cse1 .cse8 .cse9 .cse4 .cse6) (or .cse7 .cse1 .cse2 .cse3 .cse4 .cse6) (or .cse14 .cse12 .cse8 .cse4) (or .cse14 .cse12 .cse3 .cse4)))) [2022-11-16 12:10:37,871 INFO L899 garLoopResultBuilder]: For program point L592(lines 592 596) no Hoare annotation was computed. [2022-11-16 12:10:37,871 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 686 712) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse11 (and .cse15 .cse13 .cse14)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse3 (and (<= 1 ~pumpRunning~0) .cse15 .cse13 (< 1 ~waterLevel~0) (<= ~waterLevel~0 2) (not .cse4))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (and (= ~pumpRunning~0 0) .cse13 .cse14)) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse10 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse2 .cse4) (or .cse6 .cse8 .cse9 .cse10 .cse4) (or .cse0 .cse2 .cse4 .cse5 .cse11 .cse12) (or .cse6 .cse7 .cse8 .cse9 .cse4) (or .cse7 .cse0 .cse9 .cse4 .cse11 .cse12) (or .cse0 .cse1 .cse3 .cse9 .cse4 .cse5) (or .cse6 .cse8 .cse2 .cse10 .cse4)))) [2022-11-16 12:10:37,871 INFO L895 garLoopResultBuilder]: At program point L592-2(lines 588 599) the Hoare annotation is: (let ((.cse18 (= ~methaneLevelCritical~0 0)) (.cse19 (<= 1 ~pumpRunning~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse17 (<= 1 ~methaneLevelCritical~0)) (.cse20 (<= ~waterLevel~0 1)) (.cse21 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= 0 ~systemActive~0))) (let ((.cse11 (and .cse19 .cse3 .cse17 .cse20 .cse21 .cse5 (not .cse6))) (.cse13 (and .cse3 .cse20 (= |old(~waterLevel~0)| ~waterLevel~0) .cse5)) (.cse1 (not (< 1 |old(~waterLevel~0)|))) (.cse4 (= ~waterLevel~0 1)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse9 (not (<= 2 |old(~waterLevel~0)|))) (.cse10 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not (<= 1 |old(~pumpRunning~0)|))) (.cse16 (and .cse19 .cse3 .cse18 .cse20 .cse21 .cse5)) (.cse12 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse15 (not .cse18)) (.cse14 (not (<= |old(~waterLevel~0)| 1))) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse17))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5) .cse6 .cse7) (or .cse8 .cse2 .cse6 .cse7 .cse9) (or .cse10 .cse0 .cse2 .cse6 .cse11 .cse12) (or .cse13 .cse0 .cse2 .cse6 .cse7 .cse11 .cse12) (or .cse14 .cse13 .cse0 .cse15 .cse16 .cse6 .cse12) (or .cse0 .cse1 .cse15 .cse6 .cse4 .cse7) (or .cse0 .cse15 .cse16 (not (= |old(~waterLevel~0)| 2)) .cse6) (or .cse8 .cse15 .cse6 .cse7 .cse9) (or .cse10 .cse0 .cse15 .cse16 .cse6 .cse12) (or .cse14 .cse8 .cse15 .cse6) (or .cse14 .cse8 .cse2 .cse6)))) [2022-11-16 12:10:37,872 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 686 712) no Hoare annotation was computed. [2022-11-16 12:10:37,872 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-16 12:10:37,872 INFO L895 garLoopResultBuilder]: At program point L196(line 196) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse12 (<= ~methaneLevelCritical~0 |timeShift_isMethaneAlarm_#res#1|)) (.cse4 (= 0 ~systemActive~0)) (.cse13 (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~6#1|)) (.cse26 (<= 1 ~methaneLevelCritical~0)) (.cse15 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse7 (= ~waterLevel~0 |timeShift_getWaterLevel_#res#1|)) (.cse28 (= ~methaneLevelCritical~0 0)) (.cse16 (< 0 (+ |timeShift_processEnvironment_~tmp~6#1| 1))) (.cse8 (= |timeShift_isMethaneLevelCritical_#res#1| ~methaneLevelCritical~0)) (.cse25 (<= ~waterLevel~0 1)) (.cse27 (<= (+ ~waterLevel~0 1) |old(~waterLevel~0)|)) (.cse17 (<= |timeShift_isMethaneAlarm_#res#1| 0)) (.cse18 (<= |timeShift_processEnvironment_~tmp~6#1| 0)) (.cse9 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~1#1| ~waterLevel~0)) (.cse11 (<= 1 ~switchedOnBeforeTS~0)) (.cse19 (<= 0 |timeShift_isMethaneAlarm_#res#1|))) (let ((.cse22 (not (< 1 |old(~waterLevel~0)|))) (.cse23 (= ~waterLevel~0 1)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse21 (and (<= 1 ~pumpRunning~0) .cse15 .cse7 .cse28 .cse16 .cse8 .cse25 .cse27 .cse17 .cse18 .cse9 .cse11 .cse19)) (.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse24 (not (= |old(~pumpRunning~0)| 0))) (.cse20 (not .cse28)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse14 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not .cse26)) (.cse3 (and .cse6 .cse7 .cse26 .cse8 .cse25 .cse27 .cse9 .cse11 .cse12 (not .cse4) .cse13))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or (and .cse6 .cse7 .cse8 .cse9 .cse10 .cse11 .cse12 .cse13) .cse1 .cse2 .cse3 .cse4 .cse14 .cse5) (or (and .cse15 .cse7 .cse16 .cse8 .cse17 .cse18 .cse9 .cse10 .cse11 .cse19) .cse1 .cse20 .cse21 .cse4 .cse14 .cse5) (or .cse1 .cse22 .cse20 .cse4 .cse14 (and .cse15 .cse7 .cse16 .cse8 .cse17 .cse18 .cse9 .cse23 .cse11 .cse19)) (or .cse24 .cse2 .cse4 .cse14 (not (<= 2 |old(~waterLevel~0)|))) (or .cse1 .cse22 .cse2 .cse4 .cse23 .cse14) (or .cse0 .cse1 .cse20 .cse21 .cse4 .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse24 .cse2 .cse4 (and .cse6 .cse7 .cse9 .cse10)) (or .cse24 .cse20 (and .cse6 .cse7 .cse25 .cse9 .cse10) .cse4 .cse14) (or .cse1 .cse2 .cse3 (not (= |old(~waterLevel~0)| 2)) .cse4)))) [2022-11-16 12:10:37,872 INFO L899 garLoopResultBuilder]: For program point L196-1(line 196) no Hoare annotation was computed. [2022-11-16 12:10:37,873 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 61 90) no Hoare annotation was computed. [2022-11-16 12:10:37,873 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 61 90) the Hoare annotation is: true [2022-11-16 12:10:37,873 INFO L902 garLoopResultBuilder]: At program point L86(lines 61 90) the Hoare annotation is: true [2022-11-16 12:10:37,873 INFO L899 garLoopResultBuilder]: For program point L82(line 82) no Hoare annotation was computed. [2022-11-16 12:10:37,873 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 79) no Hoare annotation was computed. [2022-11-16 12:10:37,873 INFO L902 garLoopResultBuilder]: At program point L75-1(lines 75 79) the Hoare annotation is: true [2022-11-16 12:10:37,874 INFO L899 garLoopResultBuilder]: For program point L72(line 72) no Hoare annotation was computed. [2022-11-16 12:10:37,874 INFO L902 garLoopResultBuilder]: At program point L71-2(lines 71 85) the Hoare annotation is: true [2022-11-16 12:10:37,874 INFO L902 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: true [2022-11-16 12:10:37,874 INFO L899 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2022-11-16 12:10:37,874 INFO L899 garLoopResultBuilder]: For program point L927(lines 927 933) no Hoare annotation was computed. [2022-11-16 12:10:37,874 INFO L895 garLoopResultBuilder]: At program point L894(lines 890 896) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:10:37,875 INFO L899 garLoopResultBuilder]: For program point L927-1(lines 927 933) no Hoare annotation was computed. [2022-11-16 12:10:37,875 INFO L895 garLoopResultBuilder]: At program point L122(lines 118 124) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:10:37,875 INFO L899 garLoopResultBuilder]: For program point L151(lines 151 158) no Hoare annotation was computed. [2022-11-16 12:10:37,875 INFO L899 garLoopResultBuilder]: For program point L919(lines 919 923) no Hoare annotation was computed. [2022-11-16 12:10:37,875 INFO L899 garLoopResultBuilder]: For program point L151-2(lines 151 158) no Hoare annotation was computed. [2022-11-16 12:10:37,875 INFO L902 garLoopResultBuilder]: At program point L135(lines 127 137) the Hoare annotation is: true [2022-11-16 12:10:37,876 INFO L895 garLoopResultBuilder]: At program point L965(lines 916 966) the Hoare annotation is: false [2022-11-16 12:10:37,876 INFO L902 garLoopResultBuilder]: At program point L160(lines 141 163) the Hoare annotation is: true [2022-11-16 12:10:37,876 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-16 12:10:37,876 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-16 12:10:37,876 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-16 12:10:37,876 INFO L895 garLoopResultBuilder]: At program point L887(lines 883 889) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:10:37,877 INFO L895 garLoopResultBuilder]: At program point L173(lines 168 175) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:10:37,877 INFO L899 garLoopResultBuilder]: For program point L937(lines 937 943) no Hoare annotation was computed. [2022-11-16 12:10:37,877 INFO L899 garLoopResultBuilder]: For program point L937-1(lines 937 943) no Hoare annotation was computed. [2022-11-16 12:10:37,877 INFO L895 garLoopResultBuilder]: At program point L962(lines 917 964) the Hoare annotation is: (let ((.cse7 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 1)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6))) [2022-11-16 12:10:37,877 INFO L895 garLoopResultBuilder]: At program point L929(line 929) the Hoare annotation is: (let ((.cse7 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 1)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6) (and .cse7 .cse1 .cse2 .cse3 .cse4 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse6) (and .cse7 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse8 .cse2 .cse3 .cse5 .cse6) (and .cse0 .cse8 .cse1 .cse2 .cse3 .cse5 .cse6))) [2022-11-16 12:10:37,878 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 12:10:37,878 INFO L895 garLoopResultBuilder]: At program point L868(lines 863 870) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse9 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7) (and .cse0 .cse8 .cse9 .cse2 .cse3 .cse4 .cse7) (and .cse10 .cse9 .cse2 .cse3 .cse4 .cse5 .cse7) (and .cse10 .cse1 .cse2 .cse3 (<= ~waterLevel~0 1) .cse4 .cse7) (and .cse10 .cse1 .cse8 .cse2 .cse3 .cse4 .cse7) (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) .cse4 .cse5 .cse7) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7))) [2022-11-16 12:10:37,878 INFO L899 garLoopResultBuilder]: For program point L955(lines 955 959) no Hoare annotation was computed. [2022-11-16 12:10:37,878 INFO L895 garLoopResultBuilder]: At program point L955-2(lines 947 960) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse8 (= 2 ~waterLevel~0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse9 (= ~methaneLevelCritical~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7) (and .cse0 .cse8 .cse9 .cse2 .cse3 .cse4 .cse7) (and .cse10 .cse9 .cse2 .cse3 .cse4 .cse5 .cse7) (and .cse10 .cse1 .cse2 .cse3 (<= ~waterLevel~0 1) .cse4 .cse7) (and .cse10 .cse1 .cse8 .cse2 .cse3 .cse4 .cse7) (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) .cse4 .cse5 .cse7) (and .cse0 .cse9 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7))) [2022-11-16 12:10:37,878 INFO L899 garLoopResultBuilder]: For program point L918(lines 917 964) no Hoare annotation was computed. [2022-11-16 12:10:37,879 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 960) no Hoare annotation was computed. [2022-11-16 12:10:37,879 INFO L895 garLoopResultBuilder]: At program point L939(line 939) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse1 (= 2 ~waterLevel~0)) (.cse9 (<= 1 ~methaneLevelCritical~0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse4 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse8 (<= ~waterLevel~0 2)) (.cse6 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse2 .cse3 .cse4 .cse5 .cse8 .cse6) (and .cse7 .cse9 .cse3 .cse4 (<= ~waterLevel~0 1) .cse5 .cse6) (and .cse7 .cse9 .cse1 .cse3 .cse4 .cse5 .cse6) (and .cse0 .cse9 .cse3 .cse4 (<= 2 ~waterLevel~0) .cse5 .cse8 .cse6) (and .cse0 .cse2 .cse3 .cse4 .cse5 .cse8 (<= 1 ~switchedOnBeforeTS~0) .cse6))) [2022-11-16 12:10:37,879 INFO L902 garLoopResultBuilder]: At program point L968(lines 907 972) the Hoare annotation is: true [2022-11-16 12:10:37,879 INFO L895 garLoopResultBuilder]: At program point L902(lines 897 905) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 12:10:37,879 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 721 745) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (<= ~waterLevel~0 2))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse2 .cse3) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|)) .cse4 (not (<= ~waterLevel~0 1)) .cse3 (not (<= 1 ~switchedOnBeforeTS~0))))) [2022-11-16 12:10:37,880 INFO L895 garLoopResultBuilder]: At program point L735(line 735) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0) (not .cse3)))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) .cse1 .cse2 .cse3) (or (not (<= 1 |old(~pumpRunning~0)|)) .cse4 (not (<= ~waterLevel~0 1)) .cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 .cse4 .cse1 .cse2 .cse3)))) [2022-11-16 12:10:37,880 INFO L899 garLoopResultBuilder]: For program point L669(lines 669 675) no Hoare annotation was computed. [2022-11-16 12:10:37,880 INFO L895 garLoopResultBuilder]: At program point L859(lines 844 862) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0))) (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (and .cse6 (= 2 ~waterLevel~0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (<= ~waterLevel~0 2))) (.cse5 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse6 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (<= 1 |old(~pumpRunning~0)|)) .cse0 (not (<= ~waterLevel~0 1)) .cse1 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse2 .cse3 (not (<= 1 ~methaneLevelCritical~0)) .cse4 .cse5 .cse1) (or .cse2 .cse3 .cse0 .cse4 .cse5 .cse1)))) [2022-11-16 12:10:37,880 INFO L899 garLoopResultBuilder]: For program point L729(lines 729 737) no Hoare annotation was computed. [2022-11-16 12:10:37,881 INFO L899 garLoopResultBuilder]: For program point L725(lines 725 742) no Hoare annotation was computed. [2022-11-16 12:10:37,881 INFO L899 garLoopResultBuilder]: For program point L853(lines 853 857) no Hoare annotation was computed. [2022-11-16 12:10:37,881 INFO L899 garLoopResultBuilder]: For program point L853-2(lines 853 857) no Hoare annotation was computed. [2022-11-16 12:10:37,881 INFO L895 garLoopResultBuilder]: At program point L777(lines 772 779) the Hoare annotation is: (let ((.cse1 (not (<= ~waterLevel~0 1))) (.cse4 (<= 1 ~pumpRunning~0)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= ~waterLevel~0 2))) (.cse2 (= 0 ~systemActive~0))) (and (or (not (<= 1 |old(~pumpRunning~0)|)) .cse0 .cse1 .cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse3 .cse0 .cse1 .cse2) (or .cse3 (and .cse4 (= 2 ~waterLevel~0)) (not (<= 1 ~methaneLevelCritical~0)) .cse5 .cse2) (or .cse4 .cse3 .cse0 .cse5 .cse2))) [2022-11-16 12:10:37,881 INFO L895 garLoopResultBuilder]: At program point L740(line 740) the Hoare annotation is: (let ((.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|)) .cse0 (not (<= ~waterLevel~0 1)) .cse1 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse2 .cse0 .cse3 .cse1) (or .cse2 (not (<= 1 ~methaneLevelCritical~0)) .cse3 .cse1))) [2022-11-16 12:10:37,881 INFO L899 garLoopResultBuilder]: For program point L740-1(lines 721 745) no Hoare annotation was computed. [2022-11-16 12:10:37,882 INFO L895 garLoopResultBuilder]: At program point L674(lines 665 678) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (<= ~waterLevel~0 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1))) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= ~waterLevel~0 2))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse2 .cse6 .cse4) (or (not (<= 1 |old(~pumpRunning~0)|)) .cse7 .cse3 .cse4 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 .cse1 (and .cse5 (= 2 ~waterLevel~0)) .cse7 .cse6 .cse4)))) [2022-11-16 12:10:37,882 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 721 745) no Hoare annotation was computed. [2022-11-16 12:10:37,882 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 600 611) no Hoare annotation was computed. [2022-11-16 12:10:37,882 INFO L899 garLoopResultBuilder]: For program point L604-1(lines 600 611) no Hoare annotation was computed. [2022-11-16 12:10:37,882 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 600 611) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= 1 ~pumpRunning~0))) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse2 .cse3) (or (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse6 .cse2 .cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (or .cse1 .cse6 .cse7 .cse2 .cse3))) [2022-11-16 12:10:37,883 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 799 807) no Hoare annotation was computed. [2022-11-16 12:10:37,883 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 799 807) the Hoare annotation is: true [2022-11-16 12:10:37,883 INFO L899 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 799 807) no Hoare annotation was computed. [2022-11-16 12:10:37,886 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 12:10:37,888 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 12:10:37,966 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 12:10:37 BoogieIcfgContainer [2022-11-16 12:10:37,967 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 12:10:37,968 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 12:10:37,968 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 12:10:37,969 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 12:10:37,969 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 12:10:08" (3/4) ... [2022-11-16 12:10:37,972 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 12:10:37,978 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 12:10:37,979 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 12:10:37,979 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 12:10:37,979 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 12:10:37,979 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 12:10:37,979 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 12:10:37,980 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-16 12:10:37,995 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2022-11-16 12:10:37,996 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-11-16 12:10:37,996 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-11-16 12:10:37,997 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 12:10:37,997 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 12:10:37,997 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 12:10:37,998 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 12:10:38,021 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-16 12:10:38,022 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-16 12:10:38,022 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) [2022-11-16 12:10:38,022 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) [2022-11-16 12:10:38,023 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-16 12:10:38,024 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && (((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-16 12:10:38,024 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) [2022-11-16 12:10:38,024 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(pumpRunning) == 0) || (((1 <= pumpRunning && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || (((pumpRunning == 0 && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)))) && (((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && waterLevel == \result) && 2 <= waterLevel) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS))) [2022-11-16 12:10:38,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) || !(1 <= \old(pumpRunning))) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((!(1 <= \old(pumpRunning)) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || (((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && 2 == waterLevel) && \old(waterLevel) == waterLevel)) [2022-11-16 12:10:38,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-16 12:10:38,025 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 2 == \result)) || (1 <= pumpRunning && 2 == \result)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= pumpRunning && waterLevel == \result) && 2 == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-16 12:10:38,026 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-16 12:10:38,026 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-16 12:10:38,026 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) [2022-11-16 12:10:38,027 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) [2022-11-16 12:10:38,027 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive) [2022-11-16 12:10:38,027 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || (1 <= pumpRunning && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((1 <= pumpRunning || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) [2022-11-16 12:10:38,048 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/witness.graphml [2022-11-16 12:10:38,048 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 12:10:38,049 INFO L158 Benchmark]: Toolchain (without parser) took 30750.61ms. Allocated memory was 140.5MB in the beginning and 346.0MB in the end (delta: 205.5MB). Free memory was 96.8MB in the beginning and 201.2MB in the end (delta: -104.4MB). Peak memory consumption was 100.6MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,049 INFO L158 Benchmark]: CDTParser took 0.31ms. Allocated memory is still 140.5MB. Free memory is still 114.1MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 12:10:38,050 INFO L158 Benchmark]: CACSL2BoogieTranslator took 566.02ms. Allocated memory is still 140.5MB. Free memory was 96.7MB in the beginning and 104.9MB in the end (delta: -8.2MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,050 INFO L158 Benchmark]: Boogie Procedure Inliner took 81.24ms. Allocated memory is still 140.5MB. Free memory was 104.9MB in the beginning and 102.6MB in the end (delta: 2.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,050 INFO L158 Benchmark]: Boogie Preprocessor took 60.40ms. Allocated memory is still 140.5MB. Free memory was 102.0MB in the beginning and 100.8MB in the end (delta: 1.2MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 12:10:38,051 INFO L158 Benchmark]: RCFGBuilder took 598.04ms. Allocated memory is still 140.5MB. Free memory was 100.8MB in the beginning and 81.9MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,051 INFO L158 Benchmark]: TraceAbstraction took 29354.54ms. Allocated memory was 140.5MB in the beginning and 346.0MB in the end (delta: 205.5MB). Free memory was 81.0MB in the beginning and 207.5MB in the end (delta: -126.4MB). Peak memory consumption was 180.4MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,051 INFO L158 Benchmark]: Witness Printer took 80.24ms. Allocated memory is still 346.0MB. Free memory was 207.5MB in the beginning and 201.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 12:10:38,053 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.31ms. Allocated memory is still 140.5MB. Free memory is still 114.1MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 566.02ms. Allocated memory is still 140.5MB. Free memory was 96.7MB in the beginning and 104.9MB in the end (delta: -8.2MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 81.24ms. Allocated memory is still 140.5MB. Free memory was 104.9MB in the beginning and 102.6MB in the end (delta: 2.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 60.40ms. Allocated memory is still 140.5MB. Free memory was 102.0MB in the beginning and 100.8MB in the end (delta: 1.2MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 598.04ms. Allocated memory is still 140.5MB. Free memory was 100.8MB in the beginning and 81.9MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 29354.54ms. Allocated memory was 140.5MB in the beginning and 346.0MB in the end (delta: 205.5MB). Free memory was 81.0MB in the beginning and 207.5MB in the end (delta: -126.4MB). Peak memory consumption was 180.4MB. Max. memory is 16.1GB. * Witness Printer took 80.24ms. Allocated memory is still 346.0MB. Free memory was 207.5MB in the beginning and 201.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 91 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 29.2s, OverallIterations: 13, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 6.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 15.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2772 SdHoareTripleChecker+Valid, 3.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2734 mSDsluCounter, 5936 SdHoareTripleChecker+Invalid, 3.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 4447 mSDsCounter, 849 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4420 IncrementalHoareTripleChecker+Invalid, 5269 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 849 mSolverCounterUnsat, 1489 mSDtfsCounter, 4420 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1105 GetRequests, 890 SyntacticMatches, 10 SemanticMatches, 205 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1508 ImplicationChecksByTransitivity, 2.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1121occurred in iteration=11, InterpolantAutomatonStates: 172, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.7s AutomataMinimizationTime, 13 MinimizatonAttempts, 281 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 43 LocationsWithAnnotation, 2728 PreInvPairs, 3176 NumberOfFragments, 6246 HoareAnnotationTreeSize, 2728 FomulaSimplifications, 5383 FormulaSimplificationTreeSizeReduction, 1.3s HoareSimplificationTime, 43 FomulaSimplificationsInter, 45342 FormulaSimplificationTreeSizeReductionInter, 14.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 4.3s InterpolantComputationTime, 1469 NumberOfCodeBlocks, 1469 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 1723 ConstructedInterpolants, 0 QuantifiedInterpolants, 3477 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1833 ConjunctsInSsa, 28 ConjunctsInUnsatCore, 18 InterpolantComputations, 11 PerfectInterpolantSequences, 1171/1281 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 588]: Loop Invariant Derived loop invariant: ((((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && (((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 780]: Loop Invariant Derived loop invariant: ((((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 788]: Loop Invariant Derived loop invariant: (((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) || !(1 <= \old(pumpRunning))) || ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || (((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \result <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 176]: Loop Invariant Derived loop invariant: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) <= 1) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 186]: Loop Invariant Derived loop invariant: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((((((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || ((((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(pumpRunning) == 0) || (((1 <= pumpRunning && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || (((pumpRunning == 0 && 2 == \result) && tmp == 2) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)))) && (((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && waterLevel == \result) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && waterLevel == \result) && 2 <= waterLevel) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((((((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result) && !(0 == systemActive))) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 916]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 907]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 118]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 61]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 656]: Loop Invariant Derived loop invariant: ((((((((((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 2 == \result)) || (1 <= pumpRunning && 2 == \result)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(1 <= \old(switchedOnBeforeTS))) || (((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && waterLevel == \result) && methaneLevelCritical == 0) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result))) && ((((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || ((((((pumpRunning == 0 && waterLevel == \result) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= pumpRunning && waterLevel == \result) && 2 == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || ((((((((pumpRunning == \old(pumpRunning) && waterLevel == \result) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || (((((((((pumpRunning == 0 && waterLevel == \result) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || ((pumpRunning == 0 && waterLevel == \result) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 883]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 168]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 141]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 747]: Loop Invariant Derived loop invariant: ((((((((((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || (1 <= pumpRunning && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((((!(\old(waterLevel) <= 1) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || ((((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && !(0 == systemActive)) && methaneLevelCritical <= tmp)) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((((pumpRunning == 0 && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && methaneLevelCritical <= \result) && methaneLevelCritical <= tmp)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && 0 <= \result) || !(1 <= \old(pumpRunning))) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((!(1 <= \old(pumpRunning)) || ((((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && \result <= 0) && tmp <= 0) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || !(methaneLevelCritical == 0)) || (((((((pumpRunning == \old(pumpRunning) && 0 < tmp + 1) && \result == methaneLevelCritical) && \result <= 0) && tmp <= 0) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && 0 <= \result)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= pumpRunning && 2 == waterLevel) && \old(waterLevel) == waterLevel)) - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: (((((((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || ((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 772]: Loop Invariant Derived loop invariant: ((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || (1 <= pumpRunning && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((1 <= pumpRunning || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) - InvariantResult [Line: 863]: Loop Invariant Derived loop invariant: ((((((((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || ((((((1 <= pumpRunning && 2 == waterLevel) && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || ((((((pumpRunning == 0 && 1 <= methaneLevelCritical) && 2 == waterLevel) && \result == 1) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((((((1 <= pumpRunning && 1 <= methaneLevelCritical) && \result == 1) && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || (((((((1 <= pumpRunning && methaneLevelCritical == 0) && \result == 1) && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) - InvariantResult [Line: 897]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && \result == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 665]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 1)) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: (((((((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(\old(waterLevel) <= 1) || !(1 <= \old(pumpRunning))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && ((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 890]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 624]: Loop Invariant Derived loop invariant: (((((((((((((((((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(1 <= \old(pumpRunning)) || !(1 < \old(waterLevel))) || !(1 <= methaneLevelCritical)) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((!(\old(waterLevel) <= 1) || (((pumpRunning == \old(pumpRunning) && \result == methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == 0) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(waterLevel) == 1) || !(1 <= \old(pumpRunning))) || (((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 <= methaneLevelCritical) && \result == methaneLevelCritical) && waterLevel <= 1) && waterLevel + 1 <= \old(waterLevel)) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(1 <= methaneLevelCritical)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= methaneLevelCritical)) || 0 == systemActive) - InvariantResult [Line: 844]: Loop Invariant Derived loop invariant: (((((!(1 <= \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(1 <= methaneLevelCritical)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && 2 == waterLevel)) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && tmp___0 == 0) && \result == 0)) || 0 == systemActive) RESULT: Ultimate proved your program to be correct! [2022-11-16 12:10:38,099 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c61f5d4d-44c7-4b91-8716-019029ea68f6/bin/uautomizer-tPACEb0tL8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE