./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 38b53e6a Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-38b53e6 [2022-11-25 18:32:11,974 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-25 18:32:11,978 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-25 18:32:12,003 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-25 18:32:12,004 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-25 18:32:12,006 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-25 18:32:12,007 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-25 18:32:12,010 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-25 18:32:12,012 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-25 18:32:12,013 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-25 18:32:12,015 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-25 18:32:12,016 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-25 18:32:12,017 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-25 18:32:12,018 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-25 18:32:12,020 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-25 18:32:12,021 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-25 18:32:12,023 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-25 18:32:12,024 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-25 18:32:12,027 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-25 18:32:12,029 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-25 18:32:12,031 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-25 18:32:12,033 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-25 18:32:12,035 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-25 18:32:12,036 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-25 18:32:12,041 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-25 18:32:12,042 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-25 18:32:12,042 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-25 18:32:12,043 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-25 18:32:12,044 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-25 18:32:12,045 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-25 18:32:12,046 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-25 18:32:12,047 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-25 18:32:12,048 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-25 18:32:12,050 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-25 18:32:12,051 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-25 18:32:12,052 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-25 18:32:12,053 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-25 18:32:12,053 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-25 18:32:12,054 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-25 18:32:12,055 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-25 18:32:12,056 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-25 18:32:12,057 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-11-25 18:32:12,085 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-25 18:32:12,086 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-25 18:32:12,086 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-25 18:32:12,087 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-25 18:32:12,087 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-25 18:32:12,088 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-25 18:32:12,089 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-11-25 18:32:12,089 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-11-25 18:32:12,089 INFO L138 SettingsManager]: * Use SBE=true [2022-11-25 18:32:12,090 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-25 18:32:12,090 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-25 18:32:12,090 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-25 18:32:12,090 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-25 18:32:12,091 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-25 18:32:12,091 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-25 18:32:12,091 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-25 18:32:12,092 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-25 18:32:12,092 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-25 18:32:12,092 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-25 18:32:12,092 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-25 18:32:12,093 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-25 18:32:12,093 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-25 18:32:12,093 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-11-25 18:32:12,093 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-25 18:32:12,094 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-25 18:32:12,094 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-25 18:32:12,094 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-25 18:32:12,095 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-25 18:32:12,095 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-11-25 18:32:12,095 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-25 18:32:12,095 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-11-25 18:32:12,096 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-25 18:32:12,096 INFO L138 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2022-11-25 18:32:12,096 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2022-11-25 18:32:12,096 INFO L138 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 [2022-11-25 18:32:12,438 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-25 18:32:12,466 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-25 18:32:12,470 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-25 18:32:12,471 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-25 18:32:12,472 INFO L275 PluginConnector]: CDTParser initialized [2022-11-25 18:32:12,474 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/../../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2022-11-25 18:32:16,062 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-11-25 18:32:16,472 INFO L351 CDTParser]: Found 1 translation units. [2022-11-25 18:32:16,472 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2022-11-25 18:32:16,490 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/data/cb2d414c2/588bebf1eea74e3584c2ea54dda06b5e/FLAG984a7b8f2 [2022-11-25 18:32:16,518 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/data/cb2d414c2/588bebf1eea74e3584c2ea54dda06b5e [2022-11-25 18:32:16,524 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-25 18:32:16,526 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-25 18:32:16,531 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-25 18:32:16,531 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-25 18:32:16,535 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-25 18:32:16,536 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 25.11 06:32:16" (1/1) ... [2022-11-25 18:32:16,538 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@441e0bc and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:16, skipping insertion in model container [2022-11-25 18:32:16,538 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 25.11 06:32:16" (1/1) ... [2022-11-25 18:32:16,547 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-25 18:32:16,632 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-25 18:32:16,876 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2022-11-25 18:32:17,044 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-25 18:32:17,057 INFO L203 MainTranslator]: Completed pre-run [2022-11-25 18:32:17,072 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2022-11-25 18:32:17,143 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-25 18:32:17,164 INFO L208 MainTranslator]: Completed translation [2022-11-25 18:32:17,165 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17 WrapperNode [2022-11-25 18:32:17,165 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-25 18:32:17,166 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-25 18:32:17,167 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-25 18:32:17,167 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-25 18:32:17,176 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,196 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,250 INFO L138 Inliner]: procedures = 55, calls = 98, calls flagged for inlining = 24, calls inlined = 20, statements flattened = 201 [2022-11-25 18:32:17,253 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-25 18:32:17,254 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-25 18:32:17,254 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-25 18:32:17,254 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-25 18:32:17,269 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,269 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,272 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,272 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,277 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,283 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,300 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,302 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,304 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-25 18:32:17,305 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-25 18:32:17,305 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-25 18:32:17,305 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-25 18:32:17,306 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (1/1) ... [2022-11-25 18:32:17,325 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-25 18:32:17,338 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 [2022-11-25 18:32:17,364 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-25 18:32:17,387 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-25 18:32:17,414 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-25 18:32:17,415 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-25 18:32:17,415 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-25 18:32:17,415 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-25 18:32:17,416 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-25 18:32:17,416 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-25 18:32:17,418 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-25 18:32:17,418 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-25 18:32:17,419 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-25 18:32:17,419 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-25 18:32:17,419 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-25 18:32:17,419 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-25 18:32:17,419 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-25 18:32:17,420 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-25 18:32:17,420 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-25 18:32:17,420 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-25 18:32:17,556 INFO L235 CfgBuilder]: Building ICFG [2022-11-25 18:32:17,558 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-25 18:32:17,865 INFO L276 CfgBuilder]: Performing block encoding [2022-11-25 18:32:17,874 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-25 18:32:17,874 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-25 18:32:17,877 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 25.11 06:32:17 BoogieIcfgContainer [2022-11-25 18:32:17,877 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-25 18:32:17,881 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-25 18:32:17,881 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-25 18:32:17,885 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-25 18:32:17,885 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 25.11 06:32:16" (1/3) ... [2022-11-25 18:32:17,886 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@83be07a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 25.11 06:32:17, skipping insertion in model container [2022-11-25 18:32:17,886 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 25.11 06:32:17" (2/3) ... [2022-11-25 18:32:17,887 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@83be07a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 25.11 06:32:17, skipping insertion in model container [2022-11-25 18:32:17,887 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 25.11 06:32:17" (3/3) ... [2022-11-25 18:32:17,889 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product49.cil.c [2022-11-25 18:32:17,913 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-25 18:32:17,913 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-25 18:32:18,000 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-25 18:32:18,010 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@43ead1bc, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-25 18:32:18,010 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-25 18:32:18,015 INFO L276 IsEmpty]: Start isEmpty. Operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2022-11-25 18:32:18,025 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-25 18:32:18,025 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:18,026 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:18,026 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:18,033 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:18,034 INFO L85 PathProgramCache]: Analyzing trace with hash -1722090408, now seen corresponding path program 1 times [2022-11-25 18:32:18,046 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:18,047 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [180321097] [2022-11-25 18:32:18,047 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:18,048 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:18,242 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:18,361 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:18,362 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:18,362 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [180321097] [2022-11-25 18:32:18,363 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [180321097] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:18,363 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:18,364 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-25 18:32:18,366 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1853550164] [2022-11-25 18:32:18,367 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:18,372 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-25 18:32:18,373 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:18,409 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-25 18:32:18,410 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-25 18:32:18,413 INFO L87 Difference]: Start difference. First operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,462 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:18,463 INFO L93 Difference]: Finished difference Result 156 states and 215 transitions. [2022-11-25 18:32:18,464 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-25 18:32:18,465 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-11-25 18:32:18,466 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:18,476 INFO L225 Difference]: With dead ends: 156 [2022-11-25 18:32:18,477 INFO L226 Difference]: Without dead ends: 73 [2022-11-25 18:32:18,482 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-25 18:32:18,486 INFO L413 NwaCegarLoop]: 104 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 104 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:18,488 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 104 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-25 18:32:18,506 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-11-25 18:32:18,534 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-11-25 18:32:18,536 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.3333333333333333) internal successors, (76), 64 states have internal predecessors, (76), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-25 18:32:18,546 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 95 transitions. [2022-11-25 18:32:18,551 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 95 transitions. Word has length 19 [2022-11-25 18:32:18,553 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:18,555 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 95 transitions. [2022-11-25 18:32:18,556 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,556 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 95 transitions. [2022-11-25 18:32:18,558 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-25 18:32:18,562 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:18,564 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:18,564 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-25 18:32:18,565 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:18,566 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:18,568 INFO L85 PathProgramCache]: Analyzing trace with hash 1895744144, now seen corresponding path program 1 times [2022-11-25 18:32:18,569 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:18,569 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [924398962] [2022-11-25 18:32:18,569 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:18,570 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:18,600 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:18,707 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:18,708 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:18,708 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [924398962] [2022-11-25 18:32:18,708 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [924398962] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:18,709 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:18,709 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-25 18:32:18,709 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1421695641] [2022-11-25 18:32:18,710 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:18,711 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-25 18:32:18,712 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:18,713 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-25 18:32:18,713 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-25 18:32:18,713 INFO L87 Difference]: Start difference. First operand 73 states and 95 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,738 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:18,739 INFO L93 Difference]: Finished difference Result 112 states and 146 transitions. [2022-11-25 18:32:18,739 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-25 18:32:18,740 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-11-25 18:32:18,740 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:18,742 INFO L225 Difference]: With dead ends: 112 [2022-11-25 18:32:18,742 INFO L226 Difference]: Without dead ends: 64 [2022-11-25 18:32:18,743 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-25 18:32:18,745 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 12 mSDsluCounter, 66 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 148 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:18,746 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [15 Valid, 148 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-25 18:32:18,747 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-11-25 18:32:18,757 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-11-25 18:32:18,758 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3529411764705883) internal successors, (69), 58 states have internal predecessors, (69), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-25 18:32:18,760 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 83 transitions. [2022-11-25 18:32:18,760 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 83 transitions. Word has length 20 [2022-11-25 18:32:18,761 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:18,761 INFO L495 AbstractCegarLoop]: Abstraction has 64 states and 83 transitions. [2022-11-25 18:32:18,761 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,762 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 83 transitions. [2022-11-25 18:32:18,763 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-25 18:32:18,763 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:18,763 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:18,764 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-25 18:32:18,764 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:18,765 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:18,765 INFO L85 PathProgramCache]: Analyzing trace with hash 540813392, now seen corresponding path program 1 times [2022-11-25 18:32:18,765 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:18,766 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [927772693] [2022-11-25 18:32:18,766 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:18,766 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:18,796 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:18,894 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:18,894 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:18,894 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [927772693] [2022-11-25 18:32:18,895 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [927772693] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:18,895 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:18,895 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-25 18:32:18,895 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [371532473] [2022-11-25 18:32:18,896 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:18,896 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-25 18:32:18,897 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:18,897 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-25 18:32:18,898 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-25 18:32:18,898 INFO L87 Difference]: Start difference. First operand 64 states and 83 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,946 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:18,949 INFO L93 Difference]: Finished difference Result 121 states and 160 transitions. [2022-11-25 18:32:18,950 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-25 18:32:18,951 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-11-25 18:32:18,951 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:18,953 INFO L225 Difference]: With dead ends: 121 [2022-11-25 18:32:18,954 INFO L226 Difference]: Without dead ends: 64 [2022-11-25 18:32:18,955 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-25 18:32:18,957 INFO L413 NwaCegarLoop]: 81 mSDtfsCounter, 65 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 81 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:18,958 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 81 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-25 18:32:18,960 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-11-25 18:32:18,976 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-11-25 18:32:18,976 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3333333333333333) internal successors, (68), 58 states have internal predecessors, (68), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-25 18:32:18,979 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 82 transitions. [2022-11-25 18:32:18,979 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 82 transitions. Word has length 24 [2022-11-25 18:32:18,979 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:18,980 INFO L495 AbstractCegarLoop]: Abstraction has 64 states and 82 transitions. [2022-11-25 18:32:18,980 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:18,981 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 82 transitions. [2022-11-25 18:32:18,982 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2022-11-25 18:32:18,982 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:18,983 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:18,983 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-25 18:32:18,984 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:18,984 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:18,985 INFO L85 PathProgramCache]: Analyzing trace with hash 412315462, now seen corresponding path program 1 times [2022-11-25 18:32:18,985 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:18,986 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [658647728] [2022-11-25 18:32:18,986 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:18,986 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:19,036 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:19,229 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:19,232 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:19,267 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-25 18:32:19,269 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:19,272 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:19,273 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:19,273 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [658647728] [2022-11-25 18:32:19,273 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [658647728] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:19,273 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:19,274 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-25 18:32:19,274 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [720912714] [2022-11-25 18:32:19,274 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:19,275 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-25 18:32:19,275 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:19,276 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-25 18:32:19,276 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-25 18:32:19,277 INFO L87 Difference]: Start difference. First operand 64 states and 82 transitions. Second operand has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 3 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-25 18:32:19,561 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:19,562 INFO L93 Difference]: Finished difference Result 183 states and 235 transitions. [2022-11-25 18:32:19,562 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-25 18:32:19,563 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 3 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 34 [2022-11-25 18:32:19,563 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:19,565 INFO L225 Difference]: With dead ends: 183 [2022-11-25 18:32:19,565 INFO L226 Difference]: Without dead ends: 126 [2022-11-25 18:32:19,566 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2022-11-25 18:32:19,568 INFO L413 NwaCegarLoop]: 103 mSDtfsCounter, 164 mSDsluCounter, 154 mSDsCounter, 0 mSdLazyCounter, 82 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 166 SdHoareTripleChecker+Valid, 257 SdHoareTripleChecker+Invalid, 113 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 82 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:19,569 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [166 Valid, 257 Invalid, 113 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 82 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-25 18:32:19,571 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 126 states. [2022-11-25 18:32:19,606 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 126 to 120. [2022-11-25 18:32:19,610 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 120 states, 96 states have (on average 1.28125) internal successors, (123), 103 states have internal predecessors, (123), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-11-25 18:32:19,616 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 120 states to 120 states and 148 transitions. [2022-11-25 18:32:19,621 INFO L78 Accepts]: Start accepts. Automaton has 120 states and 148 transitions. Word has length 34 [2022-11-25 18:32:19,621 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:19,622 INFO L495 AbstractCegarLoop]: Abstraction has 120 states and 148 transitions. [2022-11-25 18:32:19,622 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 3 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-25 18:32:19,622 INFO L276 IsEmpty]: Start isEmpty. Operand 120 states and 148 transitions. [2022-11-25 18:32:19,624 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-25 18:32:19,625 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:19,625 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:19,628 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-25 18:32:19,629 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:19,630 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:19,630 INFO L85 PathProgramCache]: Analyzing trace with hash 1451427371, now seen corresponding path program 1 times [2022-11-25 18:32:19,630 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:19,631 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [32349022] [2022-11-25 18:32:19,631 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:19,631 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:19,664 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:19,823 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:19,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:19,881 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:19,881 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:19,882 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [32349022] [2022-11-25 18:32:19,882 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [32349022] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:19,882 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:19,882 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-25 18:32:19,883 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [574547106] [2022-11-25 18:32:19,883 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:19,883 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-25 18:32:19,884 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:19,884 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-25 18:32:19,885 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-25 18:32:19,885 INFO L87 Difference]: Start difference. First operand 120 states and 148 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:20,100 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:20,100 INFO L93 Difference]: Finished difference Result 241 states and 301 transitions. [2022-11-25 18:32:20,101 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-25 18:32:20,101 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-11-25 18:32:20,102 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:20,112 INFO L225 Difference]: With dead ends: 241 [2022-11-25 18:32:20,113 INFO L226 Difference]: Without dead ends: 128 [2022-11-25 18:32:20,115 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-11-25 18:32:20,117 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 59 mSDsluCounter, 251 mSDsCounter, 0 mSdLazyCounter, 97 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 60 SdHoareTripleChecker+Valid, 326 SdHoareTripleChecker+Invalid, 114 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 97 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:20,118 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [60 Valid, 326 Invalid, 114 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 97 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-25 18:32:20,119 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 128 states. [2022-11-25 18:32:20,160 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 128 to 123. [2022-11-25 18:32:20,160 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 123 states, 99 states have (on average 1.2727272727272727) internal successors, (126), 106 states have internal predecessors, (126), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-11-25 18:32:20,169 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 123 states to 123 states and 151 transitions. [2022-11-25 18:32:20,170 INFO L78 Accepts]: Start accepts. Automaton has 123 states and 151 transitions. Word has length 38 [2022-11-25 18:32:20,170 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:20,170 INFO L495 AbstractCegarLoop]: Abstraction has 123 states and 151 transitions. [2022-11-25 18:32:20,171 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:20,171 INFO L276 IsEmpty]: Start isEmpty. Operand 123 states and 151 transitions. [2022-11-25 18:32:20,172 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-25 18:32:20,172 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:20,172 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:20,173 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-25 18:32:20,176 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:20,177 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:20,177 INFO L85 PathProgramCache]: Analyzing trace with hash 440310121, now seen corresponding path program 1 times [2022-11-25 18:32:20,178 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:20,178 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1233789158] [2022-11-25 18:32:20,178 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:20,178 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:20,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:20,370 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:20,388 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:20,451 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:20,451 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:20,451 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1233789158] [2022-11-25 18:32:20,452 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1233789158] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:20,452 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:20,452 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-25 18:32:20,452 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1318492982] [2022-11-25 18:32:20,453 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:20,453 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-25 18:32:20,453 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:20,454 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-25 18:32:20,454 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-25 18:32:20,455 INFO L87 Difference]: Start difference. First operand 123 states and 151 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:20,634 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:20,634 INFO L93 Difference]: Finished difference Result 252 states and 316 transitions. [2022-11-25 18:32:20,635 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-25 18:32:20,635 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-11-25 18:32:20,635 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:20,637 INFO L225 Difference]: With dead ends: 252 [2022-11-25 18:32:20,637 INFO L226 Difference]: Without dead ends: 136 [2022-11-25 18:32:20,638 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=34, Invalid=56, Unknown=0, NotChecked=0, Total=90 [2022-11-25 18:32:20,640 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 130 mSDsluCounter, 176 mSDsCounter, 0 mSdLazyCounter, 87 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 132 SdHoareTripleChecker+Valid, 252 SdHoareTripleChecker+Invalid, 116 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 87 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:20,640 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [132 Valid, 252 Invalid, 116 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 87 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-25 18:32:20,641 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 136 states. [2022-11-25 18:32:20,662 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 136 to 125. [2022-11-25 18:32:20,662 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 125 states, 101 states have (on average 1.2673267326732673) internal successors, (128), 108 states have internal predecessors, (128), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-11-25 18:32:20,664 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 125 states to 125 states and 153 transitions. [2022-11-25 18:32:20,664 INFO L78 Accepts]: Start accepts. Automaton has 125 states and 153 transitions. Word has length 38 [2022-11-25 18:32:20,664 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:20,665 INFO L495 AbstractCegarLoop]: Abstraction has 125 states and 153 transitions. [2022-11-25 18:32:20,665 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:20,665 INFO L276 IsEmpty]: Start isEmpty. Operand 125 states and 153 transitions. [2022-11-25 18:32:20,666 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-25 18:32:20,667 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:20,674 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:20,674 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-25 18:32:20,674 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:20,675 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:20,675 INFO L85 PathProgramCache]: Analyzing trace with hash -580758233, now seen corresponding path program 1 times [2022-11-25 18:32:20,675 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:20,676 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1678894984] [2022-11-25 18:32:20,676 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:20,676 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:20,694 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:20,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:20,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:20,820 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:20,820 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:20,821 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1678894984] [2022-11-25 18:32:20,821 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1678894984] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:20,821 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:20,821 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-25 18:32:20,822 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [711877482] [2022-11-25 18:32:20,822 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:20,822 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-25 18:32:20,822 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:20,823 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-25 18:32:20,823 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-25 18:32:20,824 INFO L87 Difference]: Start difference. First operand 125 states and 153 transitions. Second operand has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:21,118 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:21,118 INFO L93 Difference]: Finished difference Result 355 states and 457 transitions. [2022-11-25 18:32:21,119 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-25 18:32:21,119 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-11-25 18:32:21,120 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:21,125 INFO L225 Difference]: With dead ends: 355 [2022-11-25 18:32:21,125 INFO L226 Difference]: Without dead ends: 237 [2022-11-25 18:32:21,126 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-25 18:32:21,135 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 179 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 131 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 183 SdHoareTripleChecker+Valid, 266 SdHoareTripleChecker+Invalid, 173 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 131 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:21,138 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [183 Valid, 266 Invalid, 173 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-25 18:32:21,141 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2022-11-25 18:32:21,205 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 229. [2022-11-25 18:32:21,206 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 229 states, 181 states have (on average 1.2596685082872927) internal successors, (228), 192 states have internal predecessors, (228), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2022-11-25 18:32:21,209 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 229 states to 229 states and 289 transitions. [2022-11-25 18:32:21,209 INFO L78 Accepts]: Start accepts. Automaton has 229 states and 289 transitions. Word has length 38 [2022-11-25 18:32:21,210 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:21,210 INFO L495 AbstractCegarLoop]: Abstraction has 229 states and 289 transitions. [2022-11-25 18:32:21,211 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-25 18:32:21,211 INFO L276 IsEmpty]: Start isEmpty. Operand 229 states and 289 transitions. [2022-11-25 18:32:21,222 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2022-11-25 18:32:21,223 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:21,223 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:21,223 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-25 18:32:21,224 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:21,224 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:21,224 INFO L85 PathProgramCache]: Analyzing trace with hash -360899650, now seen corresponding path program 1 times [2022-11-25 18:32:21,224 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:21,225 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [3353247] [2022-11-25 18:32:21,225 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:21,225 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:21,250 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,376 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:21,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,389 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-11-25 18:32:21,390 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,399 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:21,400 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:21,401 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [3353247] [2022-11-25 18:32:21,401 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [3353247] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:21,401 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:21,401 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-25 18:32:21,401 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1659262441] [2022-11-25 18:32:21,402 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:21,402 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-25 18:32:21,408 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:21,408 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-25 18:32:21,409 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-25 18:32:21,409 INFO L87 Difference]: Start difference. First operand 229 states and 289 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-25 18:32:21,654 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:21,654 INFO L93 Difference]: Finished difference Result 451 states and 570 transitions. [2022-11-25 18:32:21,655 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-25 18:32:21,655 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 40 [2022-11-25 18:32:21,657 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:21,661 INFO L225 Difference]: With dead ends: 451 [2022-11-25 18:32:21,661 INFO L226 Difference]: Without dead ends: 229 [2022-11-25 18:32:21,662 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-11-25 18:32:21,665 INFO L413 NwaCegarLoop]: 70 mSDtfsCounter, 99 mSDsluCounter, 233 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 102 SdHoareTripleChecker+Valid, 303 SdHoareTripleChecker+Invalid, 141 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:21,668 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [102 Valid, 303 Invalid, 141 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-25 18:32:21,673 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 229 states. [2022-11-25 18:32:21,719 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 229 to 227. [2022-11-25 18:32:21,720 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 227 states, 179 states have (on average 1.2513966480446927) internal successors, (224), 190 states have internal predecessors, (224), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2022-11-25 18:32:21,724 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 227 states to 227 states and 285 transitions. [2022-11-25 18:32:21,725 INFO L78 Accepts]: Start accepts. Automaton has 227 states and 285 transitions. Word has length 40 [2022-11-25 18:32:21,727 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:21,727 INFO L495 AbstractCegarLoop]: Abstraction has 227 states and 285 transitions. [2022-11-25 18:32:21,728 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-25 18:32:21,728 INFO L276 IsEmpty]: Start isEmpty. Operand 227 states and 285 transitions. [2022-11-25 18:32:21,733 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2022-11-25 18:32:21,733 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:21,733 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:21,734 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-25 18:32:21,734 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:21,734 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:21,735 INFO L85 PathProgramCache]: Analyzing trace with hash 2038696205, now seen corresponding path program 1 times [2022-11-25 18:32:21,735 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:21,735 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1720932190] [2022-11-25 18:32:21,735 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:21,735 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:21,757 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,905 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-25 18:32:21,906 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,916 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-11-25 18:32:21,921 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:21,934 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:21,934 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:21,934 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1720932190] [2022-11-25 18:32:21,935 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1720932190] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:21,935 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-25 18:32:21,935 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-25 18:32:21,935 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1244188924] [2022-11-25 18:32:21,935 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:21,937 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-25 18:32:21,938 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:21,939 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-25 18:32:21,939 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-25 18:32:21,940 INFO L87 Difference]: Start difference. First operand 227 states and 285 transitions. Second operand has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-25 18:32:22,382 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:22,383 INFO L93 Difference]: Finished difference Result 456 states and 585 transitions. [2022-11-25 18:32:22,383 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2022-11-25 18:32:22,383 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 42 [2022-11-25 18:32:22,384 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:22,388 INFO L225 Difference]: With dead ends: 456 [2022-11-25 18:32:22,388 INFO L226 Difference]: Without dead ends: 276 [2022-11-25 18:32:22,389 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=63, Invalid=119, Unknown=0, NotChecked=0, Total=182 [2022-11-25 18:32:22,392 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 162 mSDsluCounter, 344 mSDsCounter, 0 mSdLazyCounter, 286 mSolverCounterSat, 36 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 163 SdHoareTripleChecker+Valid, 439 SdHoareTripleChecker+Invalid, 322 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 36 IncrementalHoareTripleChecker+Valid, 286 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:22,398 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [163 Valid, 439 Invalid, 322 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [36 Valid, 286 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-25 18:32:22,399 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 276 states. [2022-11-25 18:32:22,436 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 276 to 253. [2022-11-25 18:32:22,437 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 253 states, 201 states have (on average 1.2338308457711442) internal successors, (248), 215 states have internal predecessors, (248), 24 states have call successors, (24), 23 states have call predecessors, (24), 27 states have return successors, (41), 24 states have call predecessors, (41), 24 states have call successors, (41) [2022-11-25 18:32:22,439 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 253 states to 253 states and 313 transitions. [2022-11-25 18:32:22,440 INFO L78 Accepts]: Start accepts. Automaton has 253 states and 313 transitions. Word has length 42 [2022-11-25 18:32:22,440 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:22,440 INFO L495 AbstractCegarLoop]: Abstraction has 253 states and 313 transitions. [2022-11-25 18:32:22,440 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-25 18:32:22,441 INFO L276 IsEmpty]: Start isEmpty. Operand 253 states and 313 transitions. [2022-11-25 18:32:22,442 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2022-11-25 18:32:22,442 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:22,442 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:22,442 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-25 18:32:22,443 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:22,443 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:22,444 INFO L85 PathProgramCache]: Analyzing trace with hash 871440435, now seen corresponding path program 1 times [2022-11-25 18:32:22,444 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:22,444 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [301751765] [2022-11-25 18:32:22,444 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:22,444 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:22,483 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:22,603 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-25 18:32:22,606 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:22,627 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:22,630 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:22,646 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-25 18:32:22,651 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:22,656 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-25 18:32:22,657 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:22,657 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [301751765] [2022-11-25 18:32:22,657 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [301751765] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-25 18:32:22,658 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [615106861] [2022-11-25 18:32:22,658 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:22,658 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-25 18:32:22,658 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 [2022-11-25 18:32:22,663 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-25 18:32:22,675 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-25 18:32:22,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:22,798 INFO L263 TraceCheckSpWp]: Trace formula consists of 269 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-25 18:32:22,806 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-25 18:32:23,050 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:23,051 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-25 18:32:23,235 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:23,236 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [615106861] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-25 18:32:23,236 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-25 18:32:23,237 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2022-11-25 18:32:23,237 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [350208447] [2022-11-25 18:32:23,237 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-25 18:32:23,238 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-11-25 18:32:23,238 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:23,239 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-11-25 18:32:23,239 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2022-11-25 18:32:23,240 INFO L87 Difference]: Start difference. First operand 253 states and 313 transitions. Second operand has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2022-11-25 18:32:24,589 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:24,589 INFO L93 Difference]: Finished difference Result 628 states and 814 transitions. [2022-11-25 18:32:24,590 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2022-11-25 18:32:24,594 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) Word has length 69 [2022-11-25 18:32:24,596 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:24,602 INFO L225 Difference]: With dead ends: 628 [2022-11-25 18:32:24,602 INFO L226 Difference]: Without dead ends: 424 [2022-11-25 18:32:24,604 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 185 GetRequests, 140 SyntacticMatches, 6 SemanticMatches, 39 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 407 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=312, Invalid=1328, Unknown=0, NotChecked=0, Total=1640 [2022-11-25 18:32:24,605 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 300 mSDsluCounter, 803 mSDsCounter, 0 mSdLazyCounter, 822 mSolverCounterSat, 73 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 304 SdHoareTripleChecker+Valid, 912 SdHoareTripleChecker+Invalid, 895 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 73 IncrementalHoareTripleChecker+Valid, 822 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.7s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:24,606 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [304 Valid, 912 Invalid, 895 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [73 Valid, 822 Invalid, 0 Unknown, 0 Unchecked, 0.7s Time] [2022-11-25 18:32:24,608 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 424 states. [2022-11-25 18:32:24,656 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 424 to 355. [2022-11-25 18:32:24,659 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 355 states, 282 states have (on average 1.2234042553191489) internal successors, (345), 301 states have internal predecessors, (345), 34 states have call successors, (34), 33 states have call predecessors, (34), 38 states have return successors, (61), 32 states have call predecessors, (61), 34 states have call successors, (61) [2022-11-25 18:32:24,663 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 355 states to 355 states and 440 transitions. [2022-11-25 18:32:24,663 INFO L78 Accepts]: Start accepts. Automaton has 355 states and 440 transitions. Word has length 69 [2022-11-25 18:32:24,664 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:24,664 INFO L495 AbstractCegarLoop]: Abstraction has 355 states and 440 transitions. [2022-11-25 18:32:24,664 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2022-11-25 18:32:24,664 INFO L276 IsEmpty]: Start isEmpty. Operand 355 states and 440 transitions. [2022-11-25 18:32:24,666 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 104 [2022-11-25 18:32:24,667 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:24,667 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:24,690 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-25 18:32:24,885 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-25 18:32:24,886 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:24,886 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:24,887 INFO L85 PathProgramCache]: Analyzing trace with hash 1761843705, now seen corresponding path program 1 times [2022-11-25 18:32:24,887 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:24,887 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [514678727] [2022-11-25 18:32:24,887 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:24,887 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:24,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,037 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-25 18:32:25,038 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,051 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:25,054 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,066 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-25 18:32:25,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,072 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2022-11-25 18:32:25,075 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,081 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-25 18:32:25,082 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,087 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-25 18:32:25,088 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,090 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 52 trivial. 0 not checked. [2022-11-25 18:32:25,090 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:25,090 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [514678727] [2022-11-25 18:32:25,091 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [514678727] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-25 18:32:25,091 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1350246166] [2022-11-25 18:32:25,091 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:25,091 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-25 18:32:25,092 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 [2022-11-25 18:32:25,096 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-25 18:32:25,128 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-25 18:32:25,234 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:25,236 INFO L263 TraceCheckSpWp]: Trace formula consists of 353 conjuncts, 11 conjunts are in the unsatisfiable core [2022-11-25 18:32:25,248 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-25 18:32:25,614 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 53 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-25 18:32:25,614 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-25 18:32:25,977 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 51 proven. 9 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-25 18:32:25,978 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1350246166] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-25 18:32:25,978 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-25 18:32:25,978 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 9, 8] total 20 [2022-11-25 18:32:25,979 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [543181342] [2022-11-25 18:32:25,979 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-25 18:32:25,980 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-25 18:32:25,980 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:25,981 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-25 18:32:25,981 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=71, Invalid=309, Unknown=0, NotChecked=0, Total=380 [2022-11-25 18:32:25,981 INFO L87 Difference]: Start difference. First operand 355 states and 440 transitions. Second operand has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2022-11-25 18:32:29,037 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:29,037 INFO L93 Difference]: Finished difference Result 916 states and 1194 transitions. [2022-11-25 18:32:29,038 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 42 states. [2022-11-25 18:32:29,038 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) Word has length 103 [2022-11-25 18:32:29,039 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:29,043 INFO L225 Difference]: With dead ends: 916 [2022-11-25 18:32:29,043 INFO L226 Difference]: Without dead ends: 609 [2022-11-25 18:32:29,046 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 280 GetRequests, 226 SyntacticMatches, 1 SemanticMatches, 53 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 580 ImplicationChecksByTransitivity, 1.6s TimeCoverageRelationStatistics Valid=636, Invalid=2334, Unknown=0, NotChecked=0, Total=2970 [2022-11-25 18:32:29,047 INFO L413 NwaCegarLoop]: 192 mSDtfsCounter, 605 mSDsluCounter, 1455 mSDsCounter, 0 mSdLazyCounter, 1712 mSolverCounterSat, 174 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 612 SdHoareTripleChecker+Valid, 1647 SdHoareTripleChecker+Invalid, 1886 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 174 IncrementalHoareTripleChecker+Valid, 1712 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.5s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:29,047 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [612 Valid, 1647 Invalid, 1886 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [174 Valid, 1712 Invalid, 0 Unknown, 0 Unchecked, 1.5s Time] [2022-11-25 18:32:29,049 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 609 states. [2022-11-25 18:32:29,127 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 609 to 525. [2022-11-25 18:32:29,129 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 525 states, 411 states have (on average 1.2092457420924574) internal successors, (497), 435 states have internal predecessors, (497), 56 states have call successors, (56), 54 states have call predecessors, (56), 57 states have return successors, (91), 51 states have call predecessors, (91), 56 states have call successors, (91) [2022-11-25 18:32:29,133 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 525 states to 525 states and 644 transitions. [2022-11-25 18:32:29,134 INFO L78 Accepts]: Start accepts. Automaton has 525 states and 644 transitions. Word has length 103 [2022-11-25 18:32:29,135 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:29,136 INFO L495 AbstractCegarLoop]: Abstraction has 525 states and 644 transitions. [2022-11-25 18:32:29,136 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2022-11-25 18:32:29,136 INFO L276 IsEmpty]: Start isEmpty. Operand 525 states and 644 transitions. [2022-11-25 18:32:29,145 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2022-11-25 18:32:29,145 INFO L187 NwaCegarLoop]: Found error trace [2022-11-25 18:32:29,146 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:29,161 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-25 18:32:29,352 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-25 18:32:29,353 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-25 18:32:29,353 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-25 18:32:29,354 INFO L85 PathProgramCache]: Analyzing trace with hash 1113823743, now seen corresponding path program 1 times [2022-11-25 18:32:29,354 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-11-25 18:32:29,354 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [837870727] [2022-11-25 18:32:29,354 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:29,354 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-25 18:32:29,383 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,492 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-11-25 18:32:29,494 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,504 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-11-25 18:32:29,507 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,516 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-11-25 18:32:29,518 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,522 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2022-11-25 18:32:29,528 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,589 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-11-25 18:32:29,591 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,592 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-25 18:32:29,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,595 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 95 [2022-11-25 18:32:29,596 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,598 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-11-25 18:32:29,599 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,601 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 42 proven. 9 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2022-11-25 18:32:29,601 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-11-25 18:32:29,601 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [837870727] [2022-11-25 18:32:29,602 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [837870727] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-25 18:32:29,602 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [209089354] [2022-11-25 18:32:29,602 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-25 18:32:29,602 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-25 18:32:29,603 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 [2022-11-25 18:32:29,604 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-25 18:32:29,608 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-25 18:32:29,726 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-25 18:32:29,728 INFO L263 TraceCheckSpWp]: Trace formula consists of 365 conjuncts, 5 conjunts are in the unsatisfiable core [2022-11-25 18:32:29,734 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-25 18:32:29,758 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 50 proven. 0 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-11-25 18:32:29,759 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-25 18:32:29,759 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [209089354] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-25 18:32:29,759 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-25 18:32:29,760 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 9 [2022-11-25 18:32:29,760 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1847034564] [2022-11-25 18:32:29,760 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-25 18:32:29,760 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-25 18:32:29,761 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-11-25 18:32:29,761 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-25 18:32:29,761 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=55, Unknown=0, NotChecked=0, Total=72 [2022-11-25 18:32:29,762 INFO L87 Difference]: Start difference. First operand 525 states and 644 transitions. Second operand has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-11-25 18:32:29,823 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-25 18:32:29,823 INFO L93 Difference]: Finished difference Result 676 states and 824 transitions. [2022-11-25 18:32:29,823 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-25 18:32:29,824 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 110 [2022-11-25 18:32:29,824 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-25 18:32:29,825 INFO L225 Difference]: With dead ends: 676 [2022-11-25 18:32:29,825 INFO L226 Difference]: Without dead ends: 0 [2022-11-25 18:32:29,828 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 135 GetRequests, 126 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=27, Invalid=83, Unknown=0, NotChecked=0, Total=110 [2022-11-25 18:32:29,828 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 27 mSDsluCounter, 215 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 27 SdHoareTripleChecker+Valid, 297 SdHoareTripleChecker+Invalid, 13 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-25 18:32:29,829 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [27 Valid, 297 Invalid, 13 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-25 18:32:29,830 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-25 18:32:29,830 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-25 18:32:29,831 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-25 18:32:29,831 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-25 18:32:29,832 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2022-11-25 18:32:29,832 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-25 18:32:29,832 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-25 18:32:29,833 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-11-25 18:32:29,833 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-25 18:32:29,833 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-25 18:32:29,836 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-25 18:32:29,853 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-25 18:32:30,043 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-25 18:32:30,046 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-25 18:32:32,866 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 303 309) no Hoare annotation was computed. [2022-11-25 18:32:32,867 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 303 309) the Hoare annotation is: true [2022-11-25 18:32:32,867 INFO L899 garLoopResultBuilder]: For program point L97-1(lines 93 104) no Hoare annotation was computed. [2022-11-25 18:32:32,867 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 93 104) the Hoare annotation is: true [2022-11-25 18:32:32,867 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 93 104) no Hoare annotation was computed. [2022-11-25 18:32:32,868 INFO L899 garLoopResultBuilder]: For program point L283-1(lines 282 301) no Hoare annotation was computed. [2022-11-25 18:32:32,868 INFO L899 garLoopResultBuilder]: For program point L345(lines 345 353) no Hoare annotation was computed. [2022-11-25 18:32:32,868 INFO L899 garLoopResultBuilder]: For program point L341(lines 341 358) no Hoare annotation was computed. [2022-11-25 18:32:32,868 INFO L899 garLoopResultBuilder]: For program point L73(lines 73 77) no Hoare annotation was computed. [2022-11-25 18:32:32,868 INFO L899 garLoopResultBuilder]: For program point L585(lines 585 591) no Hoare annotation was computed. [2022-11-25 18:32:32,869 INFO L895 garLoopResultBuilder]: At program point L73-2(lines 69 80) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-25 18:32:32,869 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 279 302) no Hoare annotation was computed. [2022-11-25 18:32:32,869 INFO L899 garLoopResultBuilder]: For program point L581(lines 581 594) no Hoare annotation was computed. [2022-11-25 18:32:32,870 INFO L895 garLoopResultBuilder]: At program point L581-1(lines 573 597) the Hoare annotation is: (let ((.cse6 (= 1 ~systemActive~0)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and (<= 2 ~waterLevel~0) .cse6 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) .cse5 (<= 2 |timeShift_getWaterLevel_#res#1|))) (.cse2 (not .cse6)) (.cse4 (< |old(~waterLevel~0)| 2)) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (not (<= 1 |old(~waterLevel~0)|)) (and .cse3 .cse4 .cse5)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse2 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse1 .cse2 .cse4 (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse3 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |timeShift_getWaterLevel_#res#1|)))))) [2022-11-25 18:32:32,870 INFO L895 garLoopResultBuilder]: At program point L375(lines 370 377) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-25 18:32:32,871 INFO L899 garLoopResultBuilder]: For program point L462(lines 462 466) no Hoare annotation was computed. [2022-11-25 18:32:32,871 INFO L899 garLoopResultBuilder]: For program point L462-2(lines 462 466) no Hoare annotation was computed. [2022-11-25 18:32:32,871 INFO L895 garLoopResultBuilder]: At program point L165(lines 160 168) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-25 18:32:32,871 INFO L895 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-25 18:32:32,872 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-11-25 18:32:32,872 INFO L895 garLoopResultBuilder]: At program point L356(line 356) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-25 18:32:32,872 INFO L895 garLoopResultBuilder]: At program point L356-1(lines 337 361) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 (= ~waterLevel~0 1))) (or .cse1 (< |old(~waterLevel~0)| 2) (= |old(~waterLevel~0)| ~waterLevel~0) (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse0 .cse2 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-25 18:32:32,872 INFO L899 garLoopResultBuilder]: For program point L290-1(lines 290 296) no Hoare annotation was computed. [2022-11-25 18:32:32,873 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-25 18:32:32,873 INFO L895 garLoopResultBuilder]: At program point L468(lines 453 471) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-11-25 18:32:32,873 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 279 302) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-11-25 18:32:32,874 INFO L895 garLoopResultBuilder]: At program point L142(lines 137 145) the Hoare annotation is: (let ((.cse5 (= 1 ~systemActive~0))) (let ((.cse2 (< |old(~waterLevel~0)| 2)) (.cse3 (and (<= 2 ~waterLevel~0) .cse5 (= |old(~waterLevel~0)| ~waterLevel~0) (<= 2 |timeShift_getWaterLevel_#res#1|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse5)) (.cse4 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse1 .cse2 (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |timeShift_getWaterLevel_#res#1|)) .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse4 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1)))))) [2022-11-25 18:32:32,874 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 279 302) no Hoare annotation was computed. [2022-11-25 18:32:32,874 INFO L895 garLoopResultBuilder]: At program point L394(lines 389 397) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-11-25 18:32:32,875 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-25 18:32:32,875 INFO L899 garLoopResultBuilder]: For program point L193(line 193) no Hoare annotation was computed. [2022-11-25 18:32:32,875 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 172 201) no Hoare annotation was computed. [2022-11-25 18:32:32,875 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 172 201) the Hoare annotation is: true [2022-11-25 18:32:32,875 INFO L899 garLoopResultBuilder]: For program point L186(lines 186 190) no Hoare annotation was computed. [2022-11-25 18:32:32,875 INFO L902 garLoopResultBuilder]: At program point L186-1(lines 186 190) the Hoare annotation is: true [2022-11-25 18:32:32,876 INFO L899 garLoopResultBuilder]: For program point L183(line 183) no Hoare annotation was computed. [2022-11-25 18:32:32,876 INFO L902 garLoopResultBuilder]: At program point L182-2(lines 182 196) the Hoare annotation is: true [2022-11-25 18:32:32,876 INFO L902 garLoopResultBuilder]: At program point L178(line 178) the Hoare annotation is: true [2022-11-25 18:32:32,876 INFO L899 garLoopResultBuilder]: For program point L178-1(line 178) no Hoare annotation was computed. [2022-11-25 18:32:32,876 INFO L902 garLoopResultBuilder]: At program point L197(lines 172 201) the Hoare annotation is: true [2022-11-25 18:32:32,877 INFO L899 garLoopResultBuilder]: For program point L258-2(lines 258 265) no Hoare annotation was computed. [2022-11-25 18:32:32,877 INFO L895 garLoopResultBuilder]: At program point L568(lines 563 571) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-25 18:32:32,877 INFO L902 garLoopResultBuilder]: At program point L242(lines 235 244) the Hoare annotation is: true [2022-11-25 18:32:32,877 INFO L895 garLoopResultBuilder]: At program point L560(lines 556 562) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-25 18:32:32,877 INFO L902 garLoopResultBuilder]: At program point L267(lines 248 270) the Hoare annotation is: true [2022-11-25 18:32:32,878 INFO L899 garLoopResultBuilder]: For program point L519(lines 519 523) no Hoare annotation was computed. [2022-11-25 18:32:32,878 INFO L895 garLoopResultBuilder]: At program point L519-2(lines 513 524) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-25 18:32:32,878 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-11-25 18:32:32,878 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-11-25 18:32:32,878 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-11-25 18:32:32,879 INFO L899 garLoopResultBuilder]: For program point L503(lines 503 509) no Hoare annotation was computed. [2022-11-25 18:32:32,879 INFO L899 garLoopResultBuilder]: For program point L503-1(lines 503 509) no Hoare annotation was computed. [2022-11-25 18:32:32,879 INFO L902 garLoopResultBuilder]: At program point L532(lines 473 536) the Hoare annotation is: true [2022-11-25 18:32:32,879 INFO L895 garLoopResultBuilder]: At program point L495(line 495) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-25 18:32:32,879 INFO L895 garLoopResultBuilder]: At program point L553(lines 549 555) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-25 18:32:32,880 INFO L895 garLoopResultBuilder]: At program point L231(lines 227 233) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-25 18:32:32,880 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-25 18:32:32,880 INFO L895 garLoopResultBuilder]: At program point L529(lines 482 530) the Hoare annotation is: false [2022-11-25 18:32:32,880 INFO L899 garLoopResultBuilder]: For program point L484(lines 483 528) no Hoare annotation was computed. [2022-11-25 18:32:32,880 INFO L899 garLoopResultBuilder]: For program point L513(lines 513 524) no Hoare annotation was computed. [2022-11-25 18:32:32,881 INFO L895 garLoopResultBuilder]: At program point L505(line 505) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-25 18:32:32,881 INFO L895 garLoopResultBuilder]: At program point L526(lines 483 528) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-11-25 18:32:32,881 INFO L899 garLoopResultBuilder]: For program point L493(lines 493 499) no Hoare annotation was computed. [2022-11-25 18:32:32,881 INFO L899 garLoopResultBuilder]: For program point L493-1(lines 493 499) no Hoare annotation was computed. [2022-11-25 18:32:32,881 INFO L899 garLoopResultBuilder]: For program point L485(lines 485 489) no Hoare annotation was computed. [2022-11-25 18:32:32,881 INFO L899 garLoopResultBuilder]: For program point L258(lines 258 265) no Hoare annotation was computed. [2022-11-25 18:32:32,882 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 311 335) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-25 18:32:32,882 INFO L895 garLoopResultBuilder]: At program point L155(lines 146 159) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 .cse2 (and .cse1 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))))) [2022-11-25 18:32:32,882 INFO L895 garLoopResultBuilder]: At program point L325(line 325) the Hoare annotation is: (let ((.cse3 (= 1 ~systemActive~0))) (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) .cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse3))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2))))) [2022-11-25 18:32:32,883 INFO L895 garLoopResultBuilder]: At program point L449(lines 434 452) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0))) .cse2))) [2022-11-25 18:32:32,883 INFO L899 garLoopResultBuilder]: For program point L319(lines 319 327) no Hoare annotation was computed. [2022-11-25 18:32:32,883 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 311 335) no Hoare annotation was computed. [2022-11-25 18:32:32,883 INFO L899 garLoopResultBuilder]: For program point L315(lines 315 332) no Hoare annotation was computed. [2022-11-25 18:32:32,883 INFO L899 garLoopResultBuilder]: For program point L443(lines 443 447) no Hoare annotation was computed. [2022-11-25 18:32:32,884 INFO L899 garLoopResultBuilder]: For program point L443-2(lines 443 447) no Hoare annotation was computed. [2022-11-25 18:32:32,884 INFO L899 garLoopResultBuilder]: For program point L150(lines 150 156) no Hoare annotation was computed. [2022-11-25 18:32:32,884 INFO L895 garLoopResultBuilder]: At program point L367(lines 362 369) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-11-25 18:32:32,884 INFO L895 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-11-25 18:32:32,884 INFO L899 garLoopResultBuilder]: For program point L330-1(lines 311 335) no Hoare annotation was computed. [2022-11-25 18:32:32,885 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 81 92) no Hoare annotation was computed. [2022-11-25 18:32:32,885 INFO L899 garLoopResultBuilder]: For program point L85-1(lines 81 92) no Hoare annotation was computed. [2022-11-25 18:32:32,885 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 81 92) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-25 18:32:32,889 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-25 18:32:32,892 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-25 18:32:32,922 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 25.11 06:32:32 BoogieIcfgContainer [2022-11-25 18:32:32,922 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-25 18:32:32,923 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-25 18:32:32,923 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-25 18:32:32,924 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-25 18:32:32,924 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 25.11 06:32:17" (3/4) ... [2022-11-25 18:32:32,928 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-25 18:32:32,936 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-25 18:32:32,936 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-25 18:32:32,936 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-25 18:32:32,936 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-25 18:32:32,937 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-25 18:32:32,937 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-25 18:32:32,944 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 25 nodes and edges [2022-11-25 18:32:32,945 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 8 nodes and edges [2022-11-25 18:32:32,946 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 4 nodes and edges [2022-11-25 18:32:32,946 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-25 18:32:32,946 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-25 18:32:32,978 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-11-25 18:32:32,978 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || (((((((1 <= tmp && \result == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-11-25 18:32:32,979 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-11-25 18:32:32,980 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) < 2) && \old(waterLevel) == waterLevel)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) [2022-11-25 18:32:32,980 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning) && \result == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-11-25 18:32:32,980 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) [2022-11-25 18:32:32,981 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-25 18:32:32,981 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-11-25 18:32:32,981 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (((pumpRunning == 0 && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || !(1 == systemActive)) [2022-11-25 18:32:32,982 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-11-25 18:32:32,982 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) [2022-11-25 18:32:32,982 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) [2022-11-25 18:32:33,006 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/witness.graphml [2022-11-25 18:32:33,007 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-25 18:32:33,007 INFO L158 Benchmark]: Toolchain (without parser) took 16481.59ms. Allocated memory was 130.0MB in the beginning and 201.3MB in the end (delta: 71.3MB). Free memory was 91.9MB in the beginning and 64.4MB in the end (delta: 27.5MB). Peak memory consumption was 100.3MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,008 INFO L158 Benchmark]: CDTParser took 0.38ms. Allocated memory is still 130.0MB. Free memory is still 102.0MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-25 18:32:33,008 INFO L158 Benchmark]: CACSL2BoogieTranslator took 634.97ms. Allocated memory is still 130.0MB. Free memory was 91.5MB in the beginning and 73.1MB in the end (delta: 18.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,009 INFO L158 Benchmark]: Boogie Procedure Inliner took 86.87ms. Allocated memory is still 130.0MB. Free memory was 73.1MB in the beginning and 71.0MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,009 INFO L158 Benchmark]: Boogie Preprocessor took 50.32ms. Allocated memory is still 130.0MB. Free memory was 71.0MB in the beginning and 69.3MB in the end (delta: 1.7MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-25 18:32:33,009 INFO L158 Benchmark]: RCFGBuilder took 572.73ms. Allocated memory is still 130.0MB. Free memory was 69.3MB in the beginning and 53.3MB in the end (delta: 16.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,010 INFO L158 Benchmark]: TraceAbstraction took 15041.82ms. Allocated memory was 130.0MB in the beginning and 201.3MB in the end (delta: 71.3MB). Free memory was 52.5MB in the beginning and 69.7MB in the end (delta: -17.1MB). Peak memory consumption was 73.0MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,010 INFO L158 Benchmark]: Witness Printer took 83.83ms. Allocated memory is still 201.3MB. Free memory was 69.7MB in the beginning and 64.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-25 18:32:33,012 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.38ms. Allocated memory is still 130.0MB. Free memory is still 102.0MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 634.97ms. Allocated memory is still 130.0MB. Free memory was 91.5MB in the beginning and 73.1MB in the end (delta: 18.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 86.87ms. Allocated memory is still 130.0MB. Free memory was 73.1MB in the beginning and 71.0MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 50.32ms. Allocated memory is still 130.0MB. Free memory was 71.0MB in the beginning and 69.3MB in the end (delta: 1.7MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 572.73ms. Allocated memory is still 130.0MB. Free memory was 69.3MB in the beginning and 53.3MB in the end (delta: 16.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 15041.82ms. Allocated memory was 130.0MB in the beginning and 201.3MB in the end (delta: 71.3MB). Free memory was 52.5MB in the beginning and 69.7MB in the end (delta: -17.1MB). Peak memory consumption was 73.0MB. Max. memory is 16.1GB. * Witness Printer took 83.83ms. Allocated memory is still 201.3MB. Free memory was 69.7MB in the beginning and 64.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 82 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 14.9s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 6.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1829 SdHoareTripleChecker+Valid, 3.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1802 mSDsluCounter, 5032 SdHoareTripleChecker+Invalid, 2.8s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3848 mSDsCounter, 421 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3354 IncrementalHoareTripleChecker+Invalid, 3775 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 421 mSolverCounterUnsat, 1184 mSDtfsCounter, 3354 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 688 GetRequests, 531 SyntacticMatches, 8 SemanticMatches, 149 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1014 ImplicationChecksByTransitivity, 2.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=525occurred in iteration=11, InterpolantAutomatonStates: 138, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 12 MinimizatonAttempts, 208 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 977 PreInvPairs, 1057 NumberOfFragments, 915 HoareAnnotationTreeSize, 977 FomulaSimplifications, 612 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 38 FomulaSimplificationsInter, 4889 FormulaSimplificationTreeSizeReductionInter, 2.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 3.2s InterpolantComputationTime, 857 NumberOfCodeBlocks, 857 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1012 ConstructedInterpolants, 0 QuantifiedInterpolants, 1944 SizeOfPredicates, 10 NumberOfNonLiveVariables, 987 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 17 InterpolantComputations, 10 PerfectInterpolantSequences, 344/382 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 337]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || (((((((1 <= tmp && \result == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 453]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 556]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 362]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) - InvariantResult [Line: 482]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 172]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 473]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 248]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 69]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 389]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 434]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (((pumpRunning == 0 && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || !(1 == systemActive)) - InvariantResult [Line: 483]: Loop Invariant Derived loop invariant: ((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 227]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 160]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning) && \result == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 235]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 573]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) < 2) && \old(waterLevel) == waterLevel)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) - InvariantResult [Line: 563]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 370]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) - InvariantResult [Line: 146]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) RESULT: Ultimate proved your program to be correct! [2022-11-25 18:32:33,055 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_a73bfe80-e795-4912-9030-3a70c04f65c5/bin/uautomizer-ZsLfNo2U6R/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE