./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version b5237d83 Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 690d9fe310e470fa54abb43d61d054401e7692fe0de366fc3accadb640a888e5 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-b5237d8 [2022-11-21 17:11:50,354 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-21 17:11:50,356 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-21 17:11:50,387 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-21 17:11:50,388 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-21 17:11:50,389 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-21 17:11:50,390 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-21 17:11:50,398 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-21 17:11:50,400 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-21 17:11:50,401 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-21 17:11:50,402 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-21 17:11:50,403 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-21 17:11:50,404 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-21 17:11:50,405 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-21 17:11:50,406 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-21 17:11:50,412 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-21 17:11:50,414 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-21 17:11:50,422 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-21 17:11:50,425 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-21 17:11:50,431 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-21 17:11:50,433 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-21 17:11:50,434 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-21 17:11:50,435 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-21 17:11:50,436 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-21 17:11:50,440 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-21 17:11:50,440 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-21 17:11:50,441 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-21 17:11:50,442 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-21 17:11:50,442 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-21 17:11:50,443 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-21 17:11:50,444 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-21 17:11:50,445 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-21 17:11:50,446 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-21 17:11:50,446 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-21 17:11:50,448 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-21 17:11:50,448 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-21 17:11:50,449 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-21 17:11:50,449 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-21 17:11:50,450 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-21 17:11:50,451 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-21 17:11:50,452 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-21 17:11:50,453 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-21 17:11:50,478 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-21 17:11:50,479 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-21 17:11:50,479 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-21 17:11:50,480 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-21 17:11:50,480 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-21 17:11:50,481 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-21 17:11:50,481 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-21 17:11:50,481 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-21 17:11:50,482 INFO L138 SettingsManager]: * Use SBE=true [2022-11-21 17:11:50,482 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-21 17:11:50,482 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-21 17:11:50,482 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-21 17:11:50,483 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-21 17:11:50,483 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-21 17:11:50,483 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-21 17:11:50,483 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-21 17:11:50,483 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-21 17:11:50,484 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-21 17:11:50,484 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-21 17:11:50,484 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-21 17:11:50,484 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-21 17:11:50,484 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-21 17:11:50,485 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-21 17:11:50,485 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-21 17:11:50,485 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-21 17:11:50,485 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-21 17:11:50,486 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-21 17:11:50,486 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-21 17:11:50,486 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-21 17:11:50,486 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-21 17:11:50,486 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-11-21 17:11:50,487 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-21 17:11:50,487 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-21 17:11:50,487 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 690d9fe310e470fa54abb43d61d054401e7692fe0de366fc3accadb640a888e5 [2022-11-21 17:11:50,730 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-21 17:11:50,773 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-21 17:11:50,776 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-21 17:11:50,778 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-21 17:11:50,778 INFO L275 PluginConnector]: CDTParser initialized [2022-11-21 17:11:50,780 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/../../sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c [2022-11-21 17:11:53,919 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-11-21 17:11:54,254 INFO L351 CDTParser]: Found 1 translation units. [2022-11-21 17:11:54,255 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c [2022-11-21 17:11:54,269 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/data/6db3cf26c/244158854b2a4875b68a7552c9b9d070/FLAG0359e0daa [2022-11-21 17:11:54,286 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/data/6db3cf26c/244158854b2a4875b68a7552c9b9d070 [2022-11-21 17:11:54,289 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-21 17:11:54,290 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-21 17:11:54,292 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-21 17:11:54,292 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-21 17:11:54,296 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-21 17:11:54,297 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,298 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@5d4687f6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54, skipping insertion in model container [2022-11-21 17:11:54,298 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,307 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-21 17:11:54,339 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-21 17:11:54,550 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c[6162,6175] [2022-11-21 17:11:54,662 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-21 17:11:54,676 INFO L203 MainTranslator]: Completed pre-run [2022-11-21 17:11:54,704 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/sv-benchmarks/c/product-lines/minepump_spec2_product07.cil.c[6162,6175] [2022-11-21 17:11:54,743 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-21 17:11:54,761 INFO L208 MainTranslator]: Completed translation [2022-11-21 17:11:54,762 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54 WrapperNode [2022-11-21 17:11:54,762 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-21 17:11:54,764 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-21 17:11:54,764 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-21 17:11:54,764 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-21 17:11:54,772 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,786 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,814 INFO L138 Inliner]: procedures = 52, calls = 95, calls flagged for inlining = 19, calls inlined = 16, statements flattened = 156 [2022-11-21 17:11:54,814 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-21 17:11:54,815 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-21 17:11:54,815 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-21 17:11:54,816 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-21 17:11:54,826 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,827 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,829 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,829 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,834 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,839 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,856 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,857 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,859 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-21 17:11:54,860 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-21 17:11:54,860 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-21 17:11:54,861 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-21 17:11:54,861 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (1/1) ... [2022-11-21 17:11:54,868 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-21 17:11:54,881 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/z3 [2022-11-21 17:11:54,896 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-21 17:11:54,923 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-21 17:11:54,946 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-21 17:11:54,947 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-21 17:11:54,947 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-21 17:11:54,948 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-21 17:11:54,948 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-21 17:11:54,948 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-21 17:11:54,948 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-21 17:11:54,950 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-21 17:11:54,952 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-21 17:11:54,952 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-21 17:11:54,952 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-21 17:11:54,952 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-21 17:11:54,953 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-21 17:11:54,953 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-21 17:11:54,953 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-21 17:11:54,953 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-21 17:11:54,953 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-21 17:11:54,954 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-21 17:11:55,040 INFO L235 CfgBuilder]: Building ICFG [2022-11-21 17:11:55,042 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-21 17:11:55,421 INFO L276 CfgBuilder]: Performing block encoding [2022-11-21 17:11:55,434 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-21 17:11:55,437 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-21 17:11:55,440 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 05:11:55 BoogieIcfgContainer [2022-11-21 17:11:55,440 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-21 17:11:55,443 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-21 17:11:55,445 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-21 17:11:55,449 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-21 17:11:55,449 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.11 05:11:54" (1/3) ... [2022-11-21 17:11:55,451 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11e49968 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 05:11:55, skipping insertion in model container [2022-11-21 17:11:55,451 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 05:11:54" (2/3) ... [2022-11-21 17:11:55,453 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11e49968 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 05:11:55, skipping insertion in model container [2022-11-21 17:11:55,454 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 05:11:55" (3/3) ... [2022-11-21 17:11:55,456 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product07.cil.c [2022-11-21 17:11:55,479 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-21 17:11:55,479 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-21 17:11:55,560 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-21 17:11:55,568 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@7dc4e0c7, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-21 17:11:55,569 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-21 17:11:55,574 INFO L276 IsEmpty]: Start isEmpty. Operand has 81 states, 60 states have (on average 1.3833333333333333) internal successors, (83), 67 states have internal predecessors, (83), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-21 17:11:55,588 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-21 17:11:55,589 INFO L187 NwaCegarLoop]: Found error trace [2022-11-21 17:11:55,590 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-21 17:11:55,593 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-21 17:11:55,602 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-21 17:11:55,602 INFO L85 PathProgramCache]: Analyzing trace with hash 2077906994, now seen corresponding path program 1 times [2022-11-21 17:11:55,614 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-21 17:11:55,614 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2096901380] [2022-11-21 17:11:55,615 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-21 17:11:55,616 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-21 17:11:55,741 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:55,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-11-21 17:11:55,820 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:55,827 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-21 17:11:55,828 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-21 17:11:55,828 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2096901380] [2022-11-21 17:11:55,829 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2096901380] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-21 17:11:55,829 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-21 17:11:55,830 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-21 17:11:55,831 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [681851061] [2022-11-21 17:11:55,832 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-21 17:11:55,837 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-21 17:11:55,837 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-21 17:11:55,865 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-21 17:11:55,866 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-21 17:11:55,869 INFO L87 Difference]: Start difference. First operand has 81 states, 60 states have (on average 1.3833333333333333) internal successors, (83), 67 states have internal predecessors, (83), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:55,907 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-21 17:11:55,907 INFO L93 Difference]: Finished difference Result 153 states and 208 transitions. [2022-11-21 17:11:55,909 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-21 17:11:55,910 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2022-11-21 17:11:55,911 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-21 17:11:55,920 INFO L225 Difference]: With dead ends: 153 [2022-11-21 17:11:55,920 INFO L226 Difference]: Without dead ends: 72 [2022-11-21 17:11:55,925 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-21 17:11:55,928 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 101 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-21 17:11:55,930 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-21 17:11:55,946 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 72 states. [2022-11-21 17:11:55,968 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 72 to 72. [2022-11-21 17:11:55,970 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 72 states, 53 states have (on average 1.3018867924528301) internal successors, (69), 59 states have internal predecessors, (69), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-21 17:11:55,973 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 72 states to 72 states and 92 transitions. [2022-11-21 17:11:55,975 INFO L78 Accepts]: Start accepts. Automaton has 72 states and 92 transitions. Word has length 25 [2022-11-21 17:11:55,975 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-21 17:11:55,976 INFO L495 AbstractCegarLoop]: Abstraction has 72 states and 92 transitions. [2022-11-21 17:11:55,976 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:55,977 INFO L276 IsEmpty]: Start isEmpty. Operand 72 states and 92 transitions. [2022-11-21 17:11:55,979 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-11-21 17:11:55,979 INFO L187 NwaCegarLoop]: Found error trace [2022-11-21 17:11:55,980 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-21 17:11:55,980 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-21 17:11:55,980 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-21 17:11:55,981 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-21 17:11:55,981 INFO L85 PathProgramCache]: Analyzing trace with hash 525951112, now seen corresponding path program 1 times [2022-11-21 17:11:55,982 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-21 17:11:55,982 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1284262314] [2022-11-21 17:11:55,982 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-21 17:11:55,982 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-21 17:11:56,020 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:56,150 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2022-11-21 17:11:56,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:56,156 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-21 17:11:56,170 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-21 17:11:56,171 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1284262314] [2022-11-21 17:11:56,171 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1284262314] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-21 17:11:56,172 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-21 17:11:56,172 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-21 17:11:56,172 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1866629021] [2022-11-21 17:11:56,172 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-21 17:11:56,174 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-21 17:11:56,174 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-21 17:11:56,175 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-21 17:11:56,175 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-21 17:11:56,176 INFO L87 Difference]: Start difference. First operand 72 states and 92 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:56,201 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-21 17:11:56,203 INFO L93 Difference]: Finished difference Result 105 states and 133 transitions. [2022-11-21 17:11:56,205 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-21 17:11:56,205 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2022-11-21 17:11:56,206 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-21 17:11:56,209 INFO L225 Difference]: With dead ends: 105 [2022-11-21 17:11:56,211 INFO L226 Difference]: Without dead ends: 63 [2022-11-21 17:11:56,212 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-21 17:11:56,214 INFO L413 NwaCegarLoop]: 79 mSDtfsCounter, 16 mSDsluCounter, 58 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 137 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-21 17:11:56,215 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 137 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-21 17:11:56,216 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 63 states. [2022-11-21 17:11:56,229 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 63 to 63. [2022-11-21 17:11:56,232 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 63 states, 47 states have (on average 1.3191489361702127) internal successors, (62), 53 states have internal predecessors, (62), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-21 17:11:56,233 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 63 states to 63 states and 80 transitions. [2022-11-21 17:11:56,233 INFO L78 Accepts]: Start accepts. Automaton has 63 states and 80 transitions. Word has length 26 [2022-11-21 17:11:56,234 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-21 17:11:56,234 INFO L495 AbstractCegarLoop]: Abstraction has 63 states and 80 transitions. [2022-11-21 17:11:56,234 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:56,234 INFO L276 IsEmpty]: Start isEmpty. Operand 63 states and 80 transitions. [2022-11-21 17:11:56,236 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-11-21 17:11:56,236 INFO L187 NwaCegarLoop]: Found error trace [2022-11-21 17:11:56,236 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-21 17:11:56,236 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-21 17:11:56,237 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-21 17:11:56,237 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-21 17:11:56,237 INFO L85 PathProgramCache]: Analyzing trace with hash -1806341128, now seen corresponding path program 1 times [2022-11-21 17:11:56,238 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-21 17:11:56,238 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [273965750] [2022-11-21 17:11:56,238 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-21 17:11:56,238 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-21 17:11:56,288 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:56,501 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-21 17:11:56,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:56,508 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-21 17:11:56,509 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-21 17:11:56,510 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [273965750] [2022-11-21 17:11:56,510 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [273965750] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-21 17:11:56,510 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-21 17:11:56,510 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-21 17:11:56,511 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [896520173] [2022-11-21 17:11:56,511 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-21 17:11:56,511 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-21 17:11:56,512 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-21 17:11:56,512 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-21 17:11:56,512 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-21 17:11:56,513 INFO L87 Difference]: Start difference. First operand 63 states and 80 transitions. Second operand has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:56,871 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-21 17:11:56,871 INFO L93 Difference]: Finished difference Result 215 states and 281 transitions. [2022-11-21 17:11:56,872 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-21 17:11:56,872 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 30 [2022-11-21 17:11:56,873 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-21 17:11:56,874 INFO L225 Difference]: With dead ends: 215 [2022-11-21 17:11:56,875 INFO L226 Difference]: Without dead ends: 160 [2022-11-21 17:11:56,876 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-11-21 17:11:56,877 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 212 mSDsluCounter, 275 mSDsCounter, 0 mSdLazyCounter, 87 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 212 SdHoareTripleChecker+Valid, 376 SdHoareTripleChecker+Invalid, 118 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 87 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-21 17:11:56,878 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [212 Valid, 376 Invalid, 118 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 87 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-21 17:11:56,879 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 160 states. [2022-11-21 17:11:56,903 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 160 to 154. [2022-11-21 17:11:56,904 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 154 states, 113 states have (on average 1.3628318584070795) internal successors, (154), 127 states have internal predecessors, (154), 23 states have call successors, (23), 17 states have call predecessors, (23), 17 states have return successors, (24), 17 states have call predecessors, (24), 23 states have call successors, (24) [2022-11-21 17:11:56,907 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 154 states to 154 states and 201 transitions. [2022-11-21 17:11:56,907 INFO L78 Accepts]: Start accepts. Automaton has 154 states and 201 transitions. Word has length 30 [2022-11-21 17:11:56,907 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-21 17:11:56,908 INFO L495 AbstractCegarLoop]: Abstraction has 154 states and 201 transitions. [2022-11-21 17:11:56,908 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-21 17:11:56,908 INFO L276 IsEmpty]: Start isEmpty. Operand 154 states and 201 transitions. [2022-11-21 17:11:56,910 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-21 17:11:56,910 INFO L187 NwaCegarLoop]: Found error trace [2022-11-21 17:11:56,910 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-21 17:11:56,910 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-21 17:11:56,911 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-21 17:11:56,911 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-21 17:11:56,912 INFO L85 PathProgramCache]: Analyzing trace with hash -1533330026, now seen corresponding path program 1 times [2022-11-21 17:11:56,912 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-21 17:11:56,912 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [568041362] [2022-11-21 17:11:56,912 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-21 17:11:56,913 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-21 17:11:56,927 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:57,044 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-11-21 17:11:57,046 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:57,049 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-11-21 17:11:57,050 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-21 17:11:57,054 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-21 17:11:57,055 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-21 17:11:57,055 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [568041362] [2022-11-21 17:11:57,055 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [568041362] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-21 17:11:57,056 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-21 17:11:57,056 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-21 17:11:57,056 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [806774825] [2022-11-21 17:11:57,057 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-21 17:11:57,057 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-21 17:11:57,057 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-21 17:11:57,058 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-21 17:11:57,058 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-21 17:11:57,059 INFO L87 Difference]: Start difference. First operand 154 states and 201 transitions. Second operand has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-21 17:11:57,123 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-21 17:11:57,131 INFO L93 Difference]: Finished difference Result 274 states and 360 transitions. [2022-11-21 17:11:57,132 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-21 17:11:57,132 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 35 [2022-11-21 17:11:57,133 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-21 17:11:57,133 INFO L225 Difference]: With dead ends: 274 [2022-11-21 17:11:57,135 INFO L226 Difference]: Without dead ends: 0 [2022-11-21 17:11:57,137 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-11-21 17:11:57,143 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 38 mSDsluCounter, 101 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 154 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-21 17:11:57,146 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [38 Valid, 154 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-21 17:11:57,149 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-21 17:11:57,149 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-21 17:11:57,152 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-21 17:11:57,152 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-21 17:11:57,153 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 35 [2022-11-21 17:11:57,153 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-21 17:11:57,153 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-21 17:11:57,153 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-21 17:11:57,154 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-21 17:11:57,154 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-21 17:11:57,157 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-21 17:11:57,159 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-21 17:11:57,161 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-21 17:11:57,631 INFO L902 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 211 218) the Hoare annotation is: true [2022-11-21 17:11:57,631 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 211 218) no Hoare annotation was computed. [2022-11-21 17:11:57,631 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 211 218) no Hoare annotation was computed. [2022-11-21 17:11:57,632 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 170 176) no Hoare annotation was computed. [2022-11-21 17:11:57,632 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 170 176) the Hoare annotation is: true [2022-11-21 17:11:57,633 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 82 93) the Hoare annotation is: true [2022-11-21 17:11:57,633 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 82 93) no Hoare annotation was computed. [2022-11-21 17:11:57,633 INFO L899 garLoopResultBuilder]: For program point L86-1(lines 82 93) no Hoare annotation was computed. [2022-11-21 17:11:57,633 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 773 802) no Hoare annotation was computed. [2022-11-21 17:11:57,634 INFO L902 garLoopResultBuilder]: At program point L798(lines 773 802) the Hoare annotation is: true [2022-11-21 17:11:57,635 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 773 802) the Hoare annotation is: true [2022-11-21 17:11:57,636 INFO L899 garLoopResultBuilder]: For program point L794(line 794) no Hoare annotation was computed. [2022-11-21 17:11:57,636 INFO L899 garLoopResultBuilder]: For program point L787(lines 787 791) no Hoare annotation was computed. [2022-11-21 17:11:57,636 INFO L902 garLoopResultBuilder]: At program point L787-1(lines 787 791) the Hoare annotation is: true [2022-11-21 17:11:57,636 INFO L899 garLoopResultBuilder]: For program point L784(line 784) no Hoare annotation was computed. [2022-11-21 17:11:57,641 INFO L902 garLoopResultBuilder]: At program point L783-2(lines 783 797) the Hoare annotation is: true [2022-11-21 17:11:57,642 INFO L902 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: true [2022-11-21 17:11:57,642 INFO L899 garLoopResultBuilder]: For program point L779-1(line 779) no Hoare annotation was computed. [2022-11-21 17:11:57,643 INFO L895 garLoopResultBuilder]: At program point L192(line 192) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,643 INFO L895 garLoopResultBuilder]: At program point L188(line 188) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,643 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 146 169) no Hoare annotation was computed. [2022-11-21 17:11:57,646 INFO L895 garLoopResultBuilder]: At program point L197(line 197) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0)))) [2022-11-21 17:11:57,646 INFO L895 garLoopResultBuilder]: At program point L197-1(lines 178 202) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (not (= 0 ~systemActive~0)))) [2022-11-21 17:11:57,646 INFO L895 garLoopResultBuilder]: At program point L226(lines 219 229) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,652 INFO L899 garLoopResultBuilder]: For program point L891(lines 891 901) no Hoare annotation was computed. [2022-11-21 17:11:57,652 INFO L899 garLoopResultBuilder]: For program point L887(lines 887 904) no Hoare annotation was computed. [2022-11-21 17:11:57,652 INFO L895 garLoopResultBuilder]: At program point L887-1(lines 879 907) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-21 17:11:57,652 INFO L895 garLoopResultBuilder]: At program point L235(lines 230 238) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (= |timeShift_isPumpRunning_#res#1| 0))) [2022-11-21 17:11:57,653 INFO L899 garLoopResultBuilder]: For program point L62(lines 62 66) no Hoare annotation was computed. [2022-11-21 17:11:57,653 INFO L895 garLoopResultBuilder]: At program point L62-2(lines 58 69) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,654 INFO L899 garLoopResultBuilder]: For program point L157-1(lines 157 163) no Hoare annotation was computed. [2022-11-21 17:11:57,654 INFO L899 garLoopResultBuilder]: For program point L892(lines 892 898) no Hoare annotation was computed. [2022-11-21 17:11:57,654 INFO L899 garLoopResultBuilder]: For program point L186(lines 186 194) no Hoare annotation was computed. [2022-11-21 17:11:57,655 INFO L899 garLoopResultBuilder]: For program point L182(lines 182 199) no Hoare annotation was computed. [2022-11-21 17:11:57,655 INFO L899 garLoopResultBuilder]: For program point L401(line 401) no Hoare annotation was computed. [2022-11-21 17:11:57,655 INFO L895 garLoopResultBuilder]: At program point L224(line 224) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,656 INFO L899 garLoopResultBuilder]: For program point L224-1(line 224) no Hoare annotation was computed. [2022-11-21 17:11:57,662 INFO L899 garLoopResultBuilder]: For program point L150-1(lines 149 168) no Hoare annotation was computed. [2022-11-21 17:11:57,662 INFO L895 garLoopResultBuilder]: At program point L885(line 885) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-21 17:11:57,662 INFO L899 garLoopResultBuilder]: For program point L885-1(line 885) no Hoare annotation was computed. [2022-11-21 17:11:57,662 INFO L895 garLoopResultBuilder]: At program point L402(lines 397 404) the Hoare annotation is: (not (= |old(~pumpRunning~0)| 0)) [2022-11-21 17:11:57,663 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 146 169) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) [2022-11-21 17:11:57,663 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 146 169) no Hoare annotation was computed. [2022-11-21 17:11:57,663 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 401) no Hoare annotation was computed. [2022-11-21 17:11:57,663 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 94 102) the Hoare annotation is: true [2022-11-21 17:11:57,664 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 94 102) no Hoare annotation was computed. [2022-11-21 17:11:57,664 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 94 102) no Hoare annotation was computed. [2022-11-21 17:11:57,664 INFO L902 garLoopResultBuilder]: At program point L353(lines 292 357) the Hoare annotation is: true [2022-11-21 17:11:57,664 INFO L902 garLoopResultBuilder]: At program point L865(lines 846 868) the Hoare annotation is: true [2022-11-21 17:11:57,664 INFO L895 garLoopResultBuilder]: At program point L287(lines 275 289) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-21 17:11:57,664 INFO L899 garLoopResultBuilder]: For program point L312(lines 312 318) no Hoare annotation was computed. [2022-11-21 17:11:57,665 INFO L899 garLoopResultBuilder]: For program point L312-1(lines 312 318) no Hoare annotation was computed. [2022-11-21 17:11:57,665 INFO L899 garLoopResultBuilder]: For program point L279(lines 279 285) no Hoare annotation was computed. [2022-11-21 17:11:57,665 INFO L899 garLoopResultBuilder]: For program point L279-1(lines 279 285) no Hoare annotation was computed. [2022-11-21 17:11:57,665 INFO L899 garLoopResultBuilder]: For program point L304(lines 304 308) no Hoare annotation was computed. [2022-11-21 17:11:57,666 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-21 17:11:57,667 INFO L895 garLoopResultBuilder]: At program point L350(lines 301 351) the Hoare annotation is: false [2022-11-21 17:11:57,667 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-21 17:11:57,667 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-21 17:11:57,667 INFO L899 garLoopResultBuilder]: For program point L338(lines 338 344) no Hoare annotation was computed. [2022-11-21 17:11:57,668 INFO L895 garLoopResultBuilder]: At program point L338-2(lines 332 345) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-21 17:11:57,668 INFO L895 garLoopResultBuilder]: At program point L392(lines 387 395) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-11-21 17:11:57,668 INFO L899 garLoopResultBuilder]: For program point L322(lines 322 328) no Hoare annotation was computed. [2022-11-21 17:11:57,668 INFO L899 garLoopResultBuilder]: For program point L322-1(lines 322 328) no Hoare annotation was computed. [2022-11-21 17:11:57,668 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-21 17:11:57,669 INFO L895 garLoopResultBuilder]: At program point L384(lines 380 386) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-11-21 17:11:57,669 INFO L895 garLoopResultBuilder]: At program point L347(lines 302 349) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-21 17:11:57,669 INFO L895 garLoopResultBuilder]: At program point L314(line 314) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-21 17:11:57,670 INFO L895 garLoopResultBuilder]: At program point L281(line 281) the Hoare annotation is: false [2022-11-21 17:11:57,670 INFO L895 garLoopResultBuilder]: At program point L876(lines 871 878) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_main_~tmp~5#1| ~systemActive~0)) [2022-11-21 17:11:57,670 INFO L902 garLoopResultBuilder]: At program point L843(lines 835 845) the Hoare annotation is: true [2022-11-21 17:11:57,670 INFO L895 garLoopResultBuilder]: At program point L831(lines 827 833) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_main_~tmp~5#1| ~systemActive~0)) [2022-11-21 17:11:57,671 INFO L895 garLoopResultBuilder]: At program point L377(lines 373 379) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-11-21 17:11:57,671 INFO L899 garLoopResultBuilder]: For program point L856(lines 856 863) no Hoare annotation was computed. [2022-11-21 17:11:57,671 INFO L899 garLoopResultBuilder]: For program point L856-2(lines 856 863) no Hoare annotation was computed. [2022-11-21 17:11:57,671 INFO L899 garLoopResultBuilder]: For program point L303(lines 302 349) no Hoare annotation was computed. [2022-11-21 17:11:57,672 INFO L899 garLoopResultBuilder]: For program point L332(lines 332 345) no Hoare annotation was computed. [2022-11-21 17:11:57,672 INFO L895 garLoopResultBuilder]: At program point L324(line 324) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-21 17:11:57,672 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 70 81) no Hoare annotation was computed. [2022-11-21 17:11:57,673 INFO L899 garLoopResultBuilder]: For program point L74-1(lines 70 81) no Hoare annotation was computed. [2022-11-21 17:11:57,673 INFO L902 garLoopResultBuilder]: At program point waterRiseENTRY(lines 70 81) the Hoare annotation is: true [2022-11-21 17:11:57,678 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-11-21 17:11:57,680 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-21 17:11:57,702 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.11 05:11:57 BoogieIcfgContainer [2022-11-21 17:11:57,702 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-21 17:11:57,703 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-21 17:11:57,703 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-21 17:11:57,703 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-21 17:11:57,704 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 05:11:55" (3/4) ... [2022-11-21 17:11:57,707 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-21 17:11:57,714 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-21 17:11:57,715 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-21 17:11:57,720 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 19 nodes and edges [2022-11-21 17:11:57,721 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 8 nodes and edges [2022-11-21 17:11:57,721 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 4 nodes and edges [2022-11-21 17:11:57,722 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-21 17:11:57,722 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-21 17:11:57,748 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive [2022-11-21 17:11:57,749 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && tmp == systemActive [2022-11-21 17:11:57,749 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && tmp == systemActive [2022-11-21 17:11:57,750 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-21 17:11:57,750 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(0 == systemActive)) [2022-11-21 17:11:57,751 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || pumpRunning == 0 [2022-11-21 17:11:57,751 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-21 17:11:57,752 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0) [2022-11-21 17:11:57,752 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) [2022-11-21 17:11:57,775 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/witness.graphml [2022-11-21 17:11:57,775 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-21 17:11:57,776 INFO L158 Benchmark]: Toolchain (without parser) took 3485.76ms. Allocated memory is still 190.8MB. Free memory was 156.9MB in the beginning and 75.8MB in the end (delta: 81.1MB). Peak memory consumption was 81.8MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,776 INFO L158 Benchmark]: CDTParser took 0.36ms. Allocated memory is still 138.4MB. Free memory is still 81.7MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-21 17:11:57,776 INFO L158 Benchmark]: CACSL2BoogieTranslator took 471.12ms. Allocated memory is still 190.8MB. Free memory was 156.9MB in the beginning and 138.7MB in the end (delta: 18.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,777 INFO L158 Benchmark]: Boogie Procedure Inliner took 50.75ms. Allocated memory is still 190.8MB. Free memory was 138.1MB in the beginning and 136.6MB in the end (delta: 1.4MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-21 17:11:57,777 INFO L158 Benchmark]: Boogie Preprocessor took 44.30ms. Allocated memory is still 190.8MB. Free memory was 136.6MB in the beginning and 134.6MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,777 INFO L158 Benchmark]: RCFGBuilder took 580.51ms. Allocated memory is still 190.8MB. Free memory was 134.6MB in the beginning and 119.9MB in the end (delta: 14.7MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,778 INFO L158 Benchmark]: TraceAbstraction took 2258.94ms. Allocated memory is still 190.8MB. Free memory was 119.2MB in the beginning and 81.1MB in the end (delta: 38.1MB). Peak memory consumption was 39.8MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,778 INFO L158 Benchmark]: Witness Printer took 72.70ms. Allocated memory is still 190.8MB. Free memory was 81.1MB in the beginning and 75.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-21 17:11:57,780 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.36ms. Allocated memory is still 138.4MB. Free memory is still 81.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 471.12ms. Allocated memory is still 190.8MB. Free memory was 156.9MB in the beginning and 138.7MB in the end (delta: 18.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 50.75ms. Allocated memory is still 190.8MB. Free memory was 138.1MB in the beginning and 136.6MB in the end (delta: 1.4MB). There was no memory consumed. Max. memory is 16.1GB. * Boogie Preprocessor took 44.30ms. Allocated memory is still 190.8MB. Free memory was 136.6MB in the beginning and 134.6MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 580.51ms. Allocated memory is still 190.8MB. Free memory was 134.6MB in the beginning and 119.9MB in the end (delta: 14.7MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. * TraceAbstraction took 2258.94ms. Allocated memory is still 190.8MB. Free memory was 119.2MB in the beginning and 81.1MB in the end (delta: 38.1MB). Peak memory consumption was 39.8MB. Max. memory is 16.1GB. * Witness Printer took 72.70ms. Allocated memory is still 190.8MB. Free memory was 81.1MB in the beginning and 75.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 401]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 81 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 2.1s, OverallIterations: 4, TraceHistogramMax: 1, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 0.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.5s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 270 SdHoareTripleChecker+Valid, 0.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 266 mSDsluCounter, 768 SdHoareTripleChecker+Invalid, 0.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 434 mSDsCounter, 34 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 102 IncrementalHoareTripleChecker+Invalid, 136 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 34 mSolverCounterUnsat, 334 mSDtfsCounter, 102 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 29 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=154occurred in iteration=3, InterpolantAutomatonStates: 16, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 6 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 37 LocationsWithAnnotation, 221 PreInvPairs, 260 NumberOfFragments, 186 HoareAnnotationTreeSize, 221 FomulaSimplifications, 42 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 37 FomulaSimplificationsInter, 590 FormulaSimplificationTreeSizeReductionInter, 0.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.6s InterpolantComputationTime, 116 NumberOfCodeBlocks, 116 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 112 ConstructedInterpolants, 0 QuantifiedInterpolants, 219 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 0/0 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 846]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 879]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || pumpRunning == 0 - InvariantResult [Line: 301]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 835]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 827]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && tmp == systemActive - InvariantResult [Line: 783]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 397]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 871]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && tmp == systemActive - InvariantResult [Line: 58]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 292]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 373]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 302]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 387]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 275]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 178]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(0 == systemActive)) - InvariantResult [Line: 380]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 773]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 219]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) - InvariantResult [Line: 230]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0) RESULT: Ultimate proved your program to be correct! [2022-11-21 17:11:57,811 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c30e81f3-49ba-43ab-b853-1afec9b2f4e9/bin/uautomizer-vX5HgA9Q3a/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE