./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 2329fc70 Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 68cd47586ea836a40d34f69dc7bca714ffc0af5c5bf2f7fbd8cfbbd6f1019685 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-2329fc7 [2022-12-13 21:47:18,290 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-12-13 21:47:18,292 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-12-13 21:47:18,310 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-12-13 21:47:18,310 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-12-13 21:47:18,311 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-12-13 21:47:18,312 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-12-13 21:47:18,314 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-12-13 21:47:18,315 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-12-13 21:47:18,316 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-12-13 21:47:18,316 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-12-13 21:47:18,318 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-12-13 21:47:18,318 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-12-13 21:47:18,319 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-12-13 21:47:18,320 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-12-13 21:47:18,321 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-12-13 21:47:18,321 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-12-13 21:47:18,322 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-12-13 21:47:18,324 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-12-13 21:47:18,325 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-12-13 21:47:18,326 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-12-13 21:47:18,328 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-12-13 21:47:18,329 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-12-13 21:47:18,329 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-12-13 21:47:18,333 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-12-13 21:47:18,333 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-12-13 21:47:18,333 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-12-13 21:47:18,334 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-12-13 21:47:18,334 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-12-13 21:47:18,335 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-12-13 21:47:18,335 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-12-13 21:47:18,336 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-12-13 21:47:18,337 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-12-13 21:47:18,337 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-12-13 21:47:18,338 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-12-13 21:47:18,338 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-12-13 21:47:18,339 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-12-13 21:47:18,339 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-12-13 21:47:18,339 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-12-13 21:47:18,340 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-12-13 21:47:18,340 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-12-13 21:47:18,341 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-12-13 21:47:18,366 INFO L113 SettingsManager]: Loading preferences was successful [2022-12-13 21:47:18,367 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-12-13 21:47:18,372 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-12-13 21:47:18,372 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-12-13 21:47:18,372 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-12-13 21:47:18,373 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-12-13 21:47:18,373 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-12-13 21:47:18,373 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-12-13 21:47:18,373 INFO L138 SettingsManager]: * Use SBE=true [2022-12-13 21:47:18,374 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-12-13 21:47:18,374 INFO L138 SettingsManager]: * sizeof long=4 [2022-12-13 21:47:18,374 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-12-13 21:47:18,374 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-12-13 21:47:18,374 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-12-13 21:47:18,374 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * sizeof long double=12 [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * Use constant arrays=true [2022-12-13 21:47:18,375 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-12-13 21:47:18,376 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-12-13 21:47:18,376 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-12-13 21:47:18,376 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-12-13 21:47:18,376 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-12-13 21:47:18,376 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-12-13 21:47:18,376 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-12-13 21:47:18,377 INFO L138 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2022-12-13 21:47:18,378 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2022-12-13 21:47:18,378 INFO L138 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2022-12-13 21:47:18,378 INFO L138 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 68cd47586ea836a40d34f69dc7bca714ffc0af5c5bf2f7fbd8cfbbd6f1019685 [2022-12-13 21:47:18,568 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-12-13 21:47:18,584 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-12-13 21:47:18,586 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-12-13 21:47:18,587 INFO L271 PluginConnector]: Initializing CDTParser... [2022-12-13 21:47:18,587 INFO L275 PluginConnector]: CDTParser initialized [2022-12-13 21:47:18,588 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/../../sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c [2022-12-13 21:47:21,175 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-12-13 21:47:21,351 INFO L351 CDTParser]: Found 1 translation units. [2022-12-13 21:47:21,352 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c [2022-12-13 21:47:21,363 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/data/cac0d0af7/54b40071799246e2ac45b12642cbd52c/FLAGca30bcda9 [2022-12-13 21:47:21,377 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/data/cac0d0af7/54b40071799246e2ac45b12642cbd52c [2022-12-13 21:47:21,379 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-12-13 21:47:21,381 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-12-13 21:47:21,382 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-12-13 21:47:21,382 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-12-13 21:47:21,386 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-12-13 21:47:21,386 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,387 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@4d95a37e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21, skipping insertion in model container [2022-12-13 21:47:21,388 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,395 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-12-13 21:47:21,430 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-12-13 21:47:21,571 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c[9171,9184] [2022-12-13 21:47:21,606 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-12-13 21:47:21,614 INFO L203 MainTranslator]: Completed pre-run [2022-12-13 21:47:21,638 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/sv-benchmarks/c/product-lines/minepump_spec4_product59.cil.c[9171,9184] [2022-12-13 21:47:21,661 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-12-13 21:47:21,672 INFO L208 MainTranslator]: Completed translation [2022-12-13 21:47:21,673 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21 WrapperNode [2022-12-13 21:47:21,673 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-12-13 21:47:21,674 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-12-13 21:47:21,674 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-12-13 21:47:21,674 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-12-13 21:47:21,679 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,688 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,706 INFO L138 Inliner]: procedures = 57, calls = 102, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 227 [2022-12-13 21:47:21,706 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-12-13 21:47:21,707 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-12-13 21:47:21,707 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-12-13 21:47:21,707 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-12-13 21:47:21,714 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,714 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,715 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,716 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,719 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,722 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,723 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,724 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,725 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-12-13 21:47:21,726 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-12-13 21:47:21,726 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-12-13 21:47:21,726 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-12-13 21:47:21,727 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (1/1) ... [2022-12-13 21:47:21,731 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-12-13 21:47:21,740 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 [2022-12-13 21:47:21,750 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-12-13 21:47:21,752 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-12-13 21:47:21,783 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-12-13 21:47:21,783 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-12-13 21:47:21,783 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-12-13 21:47:21,783 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-12-13 21:47:21,783 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-12-13 21:47:21,783 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-12-13 21:47:21,783 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-12-13 21:47:21,784 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-12-13 21:47:21,784 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-12-13 21:47:21,784 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-12-13 21:47:21,784 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-12-13 21:47:21,784 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-12-13 21:47:21,784 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-12-13 21:47:21,784 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-12-13 21:47:21,784 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-12-13 21:47:21,784 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-12-13 21:47:21,785 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-12-13 21:47:21,785 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-12-13 21:47:21,851 INFO L235 CfgBuilder]: Building ICFG [2022-12-13 21:47:21,853 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-12-13 21:47:22,091 INFO L276 CfgBuilder]: Performing block encoding [2022-12-13 21:47:22,097 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-12-13 21:47:22,097 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-12-13 21:47:22,099 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.12 09:47:22 BoogieIcfgContainer [2022-12-13 21:47:22,099 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-12-13 21:47:22,101 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-12-13 21:47:22,101 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-12-13 21:47:22,103 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-12-13 21:47:22,103 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 13.12 09:47:21" (1/3) ... [2022-12-13 21:47:22,104 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7e8a4d15 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.12 09:47:22, skipping insertion in model container [2022-12-13 21:47:22,104 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.12 09:47:21" (2/3) ... [2022-12-13 21:47:22,104 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7e8a4d15 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.12 09:47:22, skipping insertion in model container [2022-12-13 21:47:22,105 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.12 09:47:22" (3/3) ... [2022-12-13 21:47:22,106 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product59.cil.c [2022-12-13 21:47:22,123 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-12-13 21:47:22,123 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-12-13 21:47:22,174 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-12-13 21:47:22,179 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@587a10c0, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2022-12-13 21:47:22,179 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-12-13 21:47:22,183 INFO L276 IsEmpty]: Start isEmpty. Operand has 93 states, 72 states have (on average 1.3888888888888888) internal successors, (100), 81 states have internal predecessors, (100), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) [2022-12-13 21:47:22,189 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-12-13 21:47:22,189 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:22,189 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:22,190 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:22,194 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:22,194 INFO L85 PathProgramCache]: Analyzing trace with hash -1328460563, now seen corresponding path program 1 times [2022-12-13 21:47:22,201 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:22,201 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [532500324] [2022-12-13 21:47:22,201 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:22,202 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:22,276 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:22,318 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:22,318 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:22,319 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [532500324] [2022-12-13 21:47:22,319 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [532500324] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:22,319 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:22,319 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-12-13 21:47:22,320 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1889384491] [2022-12-13 21:47:22,321 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:22,324 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-12-13 21:47:22,325 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:22,346 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-12-13 21:47:22,346 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-12-13 21:47:22,349 INFO L87 Difference]: Start difference. First operand has 93 states, 72 states have (on average 1.3888888888888888) internal successors, (100), 81 states have internal predecessors, (100), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,376 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:22,376 INFO L93 Difference]: Finished difference Result 178 states and 243 transitions. [2022-12-13 21:47:22,377 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-12-13 21:47:22,378 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-12-13 21:47:22,378 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:22,385 INFO L225 Difference]: With dead ends: 178 [2022-12-13 21:47:22,386 INFO L226 Difference]: Without dead ends: 84 [2022-12-13 21:47:22,388 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-12-13 21:47:22,399 INFO L413 NwaCegarLoop]: 118 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 118 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:22,400 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 118 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-12-13 21:47:22,411 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 84 states. [2022-12-13 21:47:22,432 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 84 to 84. [2022-12-13 21:47:22,433 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 84 states, 65 states have (on average 1.323076923076923) internal successors, (86), 73 states have internal predecessors, (86), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-12-13 21:47:22,435 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 84 states to 84 states and 109 transitions. [2022-12-13 21:47:22,436 INFO L78 Accepts]: Start accepts. Automaton has 84 states and 109 transitions. Word has length 19 [2022-12-13 21:47:22,436 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:22,436 INFO L495 AbstractCegarLoop]: Abstraction has 84 states and 109 transitions. [2022-12-13 21:47:22,437 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,437 INFO L276 IsEmpty]: Start isEmpty. Operand 84 states and 109 transitions. [2022-12-13 21:47:22,438 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-12-13 21:47:22,438 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:22,438 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:22,438 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-12-13 21:47:22,439 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:22,439 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:22,439 INFO L85 PathProgramCache]: Analyzing trace with hash 1880549764, now seen corresponding path program 1 times [2022-12-13 21:47:22,440 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:22,440 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1596748115] [2022-12-13 21:47:22,440 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:22,440 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:22,457 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:22,513 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:22,514 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:22,514 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1596748115] [2022-12-13 21:47:22,514 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1596748115] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:22,514 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:22,514 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-12-13 21:47:22,515 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [866345032] [2022-12-13 21:47:22,515 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:22,516 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-12-13 21:47:22,516 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:22,517 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-12-13 21:47:22,517 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-13 21:47:22,517 INFO L87 Difference]: Start difference. First operand 84 states and 109 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,530 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:22,530 INFO L93 Difference]: Finished difference Result 130 states and 168 transitions. [2022-12-13 21:47:22,531 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-12-13 21:47:22,531 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-12-13 21:47:22,531 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:22,532 INFO L225 Difference]: With dead ends: 130 [2022-12-13 21:47:22,532 INFO L226 Difference]: Without dead ends: 75 [2022-12-13 21:47:22,533 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-13 21:47:22,534 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 16 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 171 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:22,534 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 171 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-12-13 21:47:22,535 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 75 states. [2022-12-13 21:47:22,540 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 75 to 75. [2022-12-13 21:47:22,540 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 75 states, 59 states have (on average 1.3389830508474576) internal successors, (79), 67 states have internal predecessors, (79), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 6 states have call predecessors, (9), 9 states have call successors, (9) [2022-12-13 21:47:22,541 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 75 states to 75 states and 97 transitions. [2022-12-13 21:47:22,542 INFO L78 Accepts]: Start accepts. Automaton has 75 states and 97 transitions. Word has length 20 [2022-12-13 21:47:22,542 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:22,542 INFO L495 AbstractCegarLoop]: Abstraction has 75 states and 97 transitions. [2022-12-13 21:47:22,542 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,542 INFO L276 IsEmpty]: Start isEmpty. Operand 75 states and 97 transitions. [2022-12-13 21:47:22,543 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-12-13 21:47:22,543 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:22,543 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:22,543 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-12-13 21:47:22,543 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:22,544 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:22,544 INFO L85 PathProgramCache]: Analyzing trace with hash 612415945, now seen corresponding path program 1 times [2022-12-13 21:47:22,544 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:22,544 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1868519111] [2022-12-13 21:47:22,545 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:22,545 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:22,561 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:22,647 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:22,647 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:22,648 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1868519111] [2022-12-13 21:47:22,648 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1868519111] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:22,648 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:22,648 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-12-13 21:47:22,648 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [713257720] [2022-12-13 21:47:22,649 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:22,649 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-12-13 21:47:22,649 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:22,650 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-12-13 21:47:22,650 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-12-13 21:47:22,650 INFO L87 Difference]: Start difference. First operand 75 states and 97 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,783 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:22,783 INFO L93 Difference]: Finished difference Result 248 states and 328 transitions. [2022-12-13 21:47:22,783 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-12-13 21:47:22,784 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-12-13 21:47:22,784 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:22,785 INFO L225 Difference]: With dead ends: 248 [2022-12-13 21:47:22,785 INFO L226 Difference]: Without dead ends: 180 [2022-12-13 21:47:22,786 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-12-13 21:47:22,787 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 261 mSDsluCounter, 315 mSDsCounter, 0 mSdLazyCounter, 87 mSolverCounterSat, 30 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 261 SdHoareTripleChecker+Valid, 429 SdHoareTripleChecker+Invalid, 117 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 30 IncrementalHoareTripleChecker+Valid, 87 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:22,787 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [261 Valid, 429 Invalid, 117 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [30 Valid, 87 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-13 21:47:22,787 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 180 states. [2022-12-13 21:47:22,803 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 180 to 174. [2022-12-13 21:47:22,804 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 174 states, 135 states have (on average 1.3703703703703705) internal successors, (185), 153 states have internal predecessors, (185), 22 states have call successors, (22), 16 states have call predecessors, (22), 16 states have return successors, (23), 14 states have call predecessors, (23), 22 states have call successors, (23) [2022-12-13 21:47:22,805 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 174 states to 174 states and 230 transitions. [2022-12-13 21:47:22,805 INFO L78 Accepts]: Start accepts. Automaton has 174 states and 230 transitions. Word has length 24 [2022-12-13 21:47:22,805 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:22,806 INFO L495 AbstractCegarLoop]: Abstraction has 174 states and 230 transitions. [2022-12-13 21:47:22,806 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,806 INFO L276 IsEmpty]: Start isEmpty. Operand 174 states and 230 transitions. [2022-12-13 21:47:22,806 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-12-13 21:47:22,806 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:22,807 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:22,807 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-12-13 21:47:22,807 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:22,807 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:22,807 INFO L85 PathProgramCache]: Analyzing trace with hash 1477369919, now seen corresponding path program 1 times [2022-12-13 21:47:22,807 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:22,807 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [966582527] [2022-12-13 21:47:22,808 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:22,808 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:22,817 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:22,887 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:22,887 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:22,887 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [966582527] [2022-12-13 21:47:22,887 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [966582527] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:22,888 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:22,888 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-12-13 21:47:22,888 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1419614116] [2022-12-13 21:47:22,888 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:22,888 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-12-13 21:47:22,888 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:22,889 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-12-13 21:47:22,889 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-12-13 21:47:22,889 INFO L87 Difference]: Start difference. First operand 174 states and 230 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,953 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:22,953 INFO L93 Difference]: Finished difference Result 491 states and 675 transitions. [2022-12-13 21:47:22,953 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-12-13 21:47:22,953 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-12-13 21:47:22,954 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:22,955 INFO L225 Difference]: With dead ends: 491 [2022-12-13 21:47:22,955 INFO L226 Difference]: Without dead ends: 324 [2022-12-13 21:47:22,956 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-12-13 21:47:22,957 INFO L413 NwaCegarLoop]: 99 mSDtfsCounter, 68 mSDsluCounter, 282 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 68 SdHoareTripleChecker+Valid, 381 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:22,957 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [68 Valid, 381 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-12-13 21:47:22,958 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 324 states. [2022-12-13 21:47:22,984 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 324 to 324. [2022-12-13 21:47:22,985 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 324 states, 250 states have (on average 1.344) internal successors, (336), 282 states have internal predecessors, (336), 44 states have call successors, (44), 32 states have call predecessors, (44), 29 states have return successors, (50), 25 states have call predecessors, (50), 44 states have call successors, (50) [2022-12-13 21:47:22,987 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 324 states to 324 states and 430 transitions. [2022-12-13 21:47:22,987 INFO L78 Accepts]: Start accepts. Automaton has 324 states and 430 transitions. Word has length 28 [2022-12-13 21:47:22,987 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:22,987 INFO L495 AbstractCegarLoop]: Abstraction has 324 states and 430 transitions. [2022-12-13 21:47:22,988 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:22,988 INFO L276 IsEmpty]: Start isEmpty. Operand 324 states and 430 transitions. [2022-12-13 21:47:22,989 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-12-13 21:47:22,989 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:22,989 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:22,989 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-12-13 21:47:22,989 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:22,990 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:22,990 INFO L85 PathProgramCache]: Analyzing trace with hash -30603644, now seen corresponding path program 1 times [2022-12-13 21:47:22,990 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:22,990 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [227261979] [2022-12-13 21:47:22,990 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:22,990 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:22,999 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,038 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:23,038 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:23,038 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [227261979] [2022-12-13 21:47:23,038 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [227261979] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:23,038 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:23,038 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-12-13 21:47:23,039 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1427924568] [2022-12-13 21:47:23,039 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:23,039 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-12-13 21:47:23,039 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:23,040 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-12-13 21:47:23,040 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-13 21:47:23,040 INFO L87 Difference]: Start difference. First operand 324 states and 430 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:23,087 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:23,088 INFO L93 Difference]: Finished difference Result 748 states and 1019 transitions. [2022-12-13 21:47:23,088 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-12-13 21:47:23,088 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-12-13 21:47:23,088 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:23,090 INFO L225 Difference]: With dead ends: 748 [2022-12-13 21:47:23,090 INFO L226 Difference]: Without dead ends: 431 [2022-12-13 21:47:23,091 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-13 21:47:23,092 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 56 mSDsluCounter, 59 mSDsCounter, 0 mSdLazyCounter, 11 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 56 SdHoareTripleChecker+Valid, 156 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 11 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:23,093 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [56 Valid, 156 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 11 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-12-13 21:47:23,093 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 431 states. [2022-12-13 21:47:23,119 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 431 to 420. [2022-12-13 21:47:23,119 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 420 states, 330 states have (on average 1.2969696969696969) internal successors, (428), 357 states have internal predecessors, (428), 47 states have call successors, (47), 45 states have call predecessors, (47), 42 states have return successors, (69), 41 states have call predecessors, (69), 47 states have call successors, (69) [2022-12-13 21:47:23,121 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 420 states to 420 states and 544 transitions. [2022-12-13 21:47:23,121 INFO L78 Accepts]: Start accepts. Automaton has 420 states and 544 transitions. Word has length 30 [2022-12-13 21:47:23,121 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:23,122 INFO L495 AbstractCegarLoop]: Abstraction has 420 states and 544 transitions. [2022-12-13 21:47:23,122 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:23,122 INFO L276 IsEmpty]: Start isEmpty. Operand 420 states and 544 transitions. [2022-12-13 21:47:23,122 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-12-13 21:47:23,123 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:23,123 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:23,123 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-12-13 21:47:23,123 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:23,123 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:23,123 INFO L85 PathProgramCache]: Analyzing trace with hash 1736818085, now seen corresponding path program 1 times [2022-12-13 21:47:23,123 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:23,124 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1898548495] [2022-12-13 21:47:23,124 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:23,124 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:23,131 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,185 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:23,187 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,190 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:23,190 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:23,190 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1898548495] [2022-12-13 21:47:23,191 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1898548495] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:23,191 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:23,191 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-12-13 21:47:23,191 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1602973] [2022-12-13 21:47:23,191 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:23,191 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-12-13 21:47:23,192 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:23,192 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-12-13 21:47:23,193 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-12-13 21:47:23,193 INFO L87 Difference]: Start difference. First operand 420 states and 544 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-12-13 21:47:23,417 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:23,417 INFO L93 Difference]: Finished difference Result 519 states and 675 transitions. [2022-12-13 21:47:23,417 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-12-13 21:47:23,418 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-12-13 21:47:23,418 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:23,423 INFO L225 Difference]: With dead ends: 519 [2022-12-13 21:47:23,423 INFO L226 Difference]: Without dead ends: 517 [2022-12-13 21:47:23,423 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-12-13 21:47:23,425 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 139 mSDsluCounter, 266 mSDsCounter, 0 mSdLazyCounter, 198 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 143 SdHoareTripleChecker+Valid, 348 SdHoareTripleChecker+Invalid, 230 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 198 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:23,425 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [143 Valid, 348 Invalid, 230 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 198 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-13 21:47:23,426 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 517 states. [2022-12-13 21:47:23,458 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 517 to 488. [2022-12-13 21:47:23,459 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 488 states, 383 states have (on average 1.279373368146214) internal successors, (490), 421 states have internal predecessors, (490), 53 states have call successors, (53), 45 states have call predecessors, (53), 51 states have return successors, (88), 45 states have call predecessors, (88), 53 states have call successors, (88) [2022-12-13 21:47:23,461 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 488 states to 488 states and 631 transitions. [2022-12-13 21:47:23,461 INFO L78 Accepts]: Start accepts. Automaton has 488 states and 631 transitions. Word has length 32 [2022-12-13 21:47:23,461 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:23,462 INFO L495 AbstractCegarLoop]: Abstraction has 488 states and 631 transitions. [2022-12-13 21:47:23,462 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-12-13 21:47:23,462 INFO L276 IsEmpty]: Start isEmpty. Operand 488 states and 631 transitions. [2022-12-13 21:47:23,463 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2022-12-13 21:47:23,463 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:23,463 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:23,463 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-12-13 21:47:23,463 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:23,463 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:23,463 INFO L85 PathProgramCache]: Analyzing trace with hash -2119024627, now seen corresponding path program 1 times [2022-12-13 21:47:23,464 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:23,464 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1812403253] [2022-12-13 21:47:23,464 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:23,464 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:23,472 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,517 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:23,518 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-12-13 21:47:23,528 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,549 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:23,549 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:23,549 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1812403253] [2022-12-13 21:47:23,549 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1812403253] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:23,549 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:23,549 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-12-13 21:47:23,550 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [105590782] [2022-12-13 21:47:23,550 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:23,550 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-12-13 21:47:23,550 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:23,551 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-12-13 21:47:23,551 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-12-13 21:47:23,551 INFO L87 Difference]: Start difference. First operand 488 states and 631 transitions. Second operand has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:23,839 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:23,839 INFO L93 Difference]: Finished difference Result 1083 states and 1452 transitions. [2022-12-13 21:47:23,839 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-12-13 21:47:23,839 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 46 [2022-12-13 21:47:23,840 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:23,843 INFO L225 Difference]: With dead ends: 1083 [2022-12-13 21:47:23,843 INFO L226 Difference]: Without dead ends: 602 [2022-12-13 21:47:23,845 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=41, Invalid=115, Unknown=0, NotChecked=0, Total=156 [2022-12-13 21:47:23,846 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 220 mSDsluCounter, 279 mSDsCounter, 0 mSdLazyCounter, 309 mSolverCounterSat, 55 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 220 SdHoareTripleChecker+Valid, 347 SdHoareTripleChecker+Invalid, 364 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 55 IncrementalHoareTripleChecker+Valid, 309 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:23,846 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [220 Valid, 347 Invalid, 364 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [55 Valid, 309 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-12-13 21:47:23,847 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 602 states. [2022-12-13 21:47:23,893 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 602 to 532. [2022-12-13 21:47:23,894 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 532 states, 421 states have (on average 1.2636579572446556) internal successors, (532), 459 states have internal predecessors, (532), 53 states have call successors, (53), 45 states have call predecessors, (53), 57 states have return successors, (96), 49 states have call predecessors, (96), 53 states have call successors, (96) [2022-12-13 21:47:23,897 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 532 states to 532 states and 681 transitions. [2022-12-13 21:47:23,898 INFO L78 Accepts]: Start accepts. Automaton has 532 states and 681 transitions. Word has length 46 [2022-12-13 21:47:23,898 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:23,898 INFO L495 AbstractCegarLoop]: Abstraction has 532 states and 681 transitions. [2022-12-13 21:47:23,898 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:23,898 INFO L276 IsEmpty]: Start isEmpty. Operand 532 states and 681 transitions. [2022-12-13 21:47:23,900 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2022-12-13 21:47:23,900 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:23,900 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:23,900 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-12-13 21:47:23,901 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:23,901 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:23,901 INFO L85 PathProgramCache]: Analyzing trace with hash -124879921, now seen corresponding path program 1 times [2022-12-13 21:47:23,901 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:23,901 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [452840093] [2022-12-13 21:47:23,901 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:23,902 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:23,912 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,946 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:23,947 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,951 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-12-13 21:47:23,954 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:23,981 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:23,981 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:23,981 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [452840093] [2022-12-13 21:47:23,981 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [452840093] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:23,981 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:23,981 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-12-13 21:47:23,981 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [989415701] [2022-12-13 21:47:23,982 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:23,982 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-12-13 21:47:23,982 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:23,982 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-12-13 21:47:23,983 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-12-13 21:47:23,983 INFO L87 Difference]: Start difference. First operand 532 states and 681 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:24,209 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:24,209 INFO L93 Difference]: Finished difference Result 1044 states and 1375 transitions. [2022-12-13 21:47:24,210 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-12-13 21:47:24,210 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 46 [2022-12-13 21:47:24,210 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:24,213 INFO L225 Difference]: With dead ends: 1044 [2022-12-13 21:47:24,213 INFO L226 Difference]: Without dead ends: 519 [2022-12-13 21:47:24,215 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-12-13 21:47:24,215 INFO L413 NwaCegarLoop]: 70 mSDtfsCounter, 146 mSDsluCounter, 266 mSDsCounter, 0 mSdLazyCounter, 248 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 146 SdHoareTripleChecker+Valid, 336 SdHoareTripleChecker+Invalid, 293 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 248 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:24,216 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [146 Valid, 336 Invalid, 293 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 248 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-13 21:47:24,217 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 519 states. [2022-12-13 21:47:24,248 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 519 to 425. [2022-12-13 21:47:24,249 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 425 states, 336 states have (on average 1.2619047619047619) internal successors, (424), 365 states have internal predecessors, (424), 44 states have call successors, (44), 38 states have call predecessors, (44), 44 states have return successors, (70), 38 states have call predecessors, (70), 44 states have call successors, (70) [2022-12-13 21:47:24,251 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 425 states to 425 states and 538 transitions. [2022-12-13 21:47:24,252 INFO L78 Accepts]: Start accepts. Automaton has 425 states and 538 transitions. Word has length 46 [2022-12-13 21:47:24,252 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:24,252 INFO L495 AbstractCegarLoop]: Abstraction has 425 states and 538 transitions. [2022-12-13 21:47:24,252 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:24,252 INFO L276 IsEmpty]: Start isEmpty. Operand 425 states and 538 transitions. [2022-12-13 21:47:24,253 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2022-12-13 21:47:24,253 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:24,253 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:24,254 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-12-13 21:47:24,254 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:24,254 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:24,254 INFO L85 PathProgramCache]: Analyzing trace with hash 1358294219, now seen corresponding path program 1 times [2022-12-13 21:47:24,254 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:24,254 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [359807580] [2022-12-13 21:47:24,254 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:24,255 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:24,265 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,329 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:24,331 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,337 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-12-13 21:47:24,339 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,349 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:24,350 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:24,350 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [359807580] [2022-12-13 21:47:24,350 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [359807580] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:24,350 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:24,350 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-12-13 21:47:24,350 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [567064097] [2022-12-13 21:47:24,350 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:24,351 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-12-13 21:47:24,351 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:24,351 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-12-13 21:47:24,351 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-12-13 21:47:24,352 INFO L87 Difference]: Start difference. First operand 425 states and 538 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:24,699 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:24,699 INFO L93 Difference]: Finished difference Result 971 states and 1304 transitions. [2022-12-13 21:47:24,700 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-12-13 21:47:24,700 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 46 [2022-12-13 21:47:24,700 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:24,703 INFO L225 Difference]: With dead ends: 971 [2022-12-13 21:47:24,704 INFO L226 Difference]: Without dead ends: 660 [2022-12-13 21:47:24,705 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 60 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-12-13 21:47:24,706 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 223 mSDsluCounter, 342 mSDsCounter, 0 mSdLazyCounter, 343 mSolverCounterSat, 57 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 225 SdHoareTripleChecker+Valid, 436 SdHoareTripleChecker+Invalid, 400 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 57 IncrementalHoareTripleChecker+Valid, 343 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:24,706 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [225 Valid, 436 Invalid, 400 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [57 Valid, 343 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-12-13 21:47:24,707 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 660 states. [2022-12-13 21:47:24,756 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 660 to 635. [2022-12-13 21:47:24,757 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 635 states, 501 states have (on average 1.2375249500998005) internal successors, (620), 538 states have internal predecessors, (620), 66 states have call successors, (66), 58 states have call predecessors, (66), 67 states have return successors, (131), 66 states have call predecessors, (131), 66 states have call successors, (131) [2022-12-13 21:47:24,761 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 635 states to 635 states and 817 transitions. [2022-12-13 21:47:24,761 INFO L78 Accepts]: Start accepts. Automaton has 635 states and 817 transitions. Word has length 46 [2022-12-13 21:47:24,762 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:24,762 INFO L495 AbstractCegarLoop]: Abstraction has 635 states and 817 transitions. [2022-12-13 21:47:24,762 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-12-13 21:47:24,762 INFO L276 IsEmpty]: Start isEmpty. Operand 635 states and 817 transitions. [2022-12-13 21:47:24,764 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 81 [2022-12-13 21:47:24,764 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:24,764 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:24,765 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-12-13 21:47:24,765 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:24,765 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:24,765 INFO L85 PathProgramCache]: Analyzing trace with hash -572504429, now seen corresponding path program 1 times [2022-12-13 21:47:24,765 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:24,765 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1713806102] [2022-12-13 21:47:24,765 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:24,766 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:24,777 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,854 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:24,855 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,863 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-12-13 21:47:24,866 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,879 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-12-13 21:47:24,882 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,889 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2022-12-13 21:47:24,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,891 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-12-13 21:47:24,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,893 INFO L134 CoverageAnalysis]: Checked inductivity of 20 backedges. 11 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-12-13 21:47:24,893 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:24,893 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1713806102] [2022-12-13 21:47:24,893 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1713806102] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-13 21:47:24,893 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [577940985] [2022-12-13 21:47:24,893 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:24,894 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-13 21:47:24,894 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 [2022-12-13 21:47:24,895 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-13 21:47:24,896 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-12-13 21:47:24,964 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:24,966 INFO L263 TraceCheckSpWp]: Trace formula consists of 298 conjuncts, 8 conjunts are in the unsatisfiable core [2022-12-13 21:47:24,973 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-13 21:47:25,075 INFO L134 CoverageAnalysis]: Checked inductivity of 20 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-12-13 21:47:25,076 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-12-13 21:47:25,174 INFO L134 CoverageAnalysis]: Checked inductivity of 20 backedges. 12 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-12-13 21:47:25,174 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [577940985] provided 0 perfect and 2 imperfect interpolant sequences [2022-12-13 21:47:25,174 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-12-13 21:47:25,174 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-12-13 21:47:25,174 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [752472245] [2022-12-13 21:47:25,175 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-12-13 21:47:25,175 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-12-13 21:47:25,175 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:25,176 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-12-13 21:47:25,176 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-12-13 21:47:25,176 INFO L87 Difference]: Start difference. First operand 635 states and 817 transitions. Second operand has 9 states, 9 states have (on average 8.333333333333334) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-12-13 21:47:25,741 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:25,741 INFO L93 Difference]: Finished difference Result 1512 states and 2051 transitions. [2022-12-13 21:47:25,741 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-12-13 21:47:25,742 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 8.333333333333334) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 80 [2022-12-13 21:47:25,742 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:25,749 INFO L225 Difference]: With dead ends: 1512 [2022-12-13 21:47:25,749 INFO L226 Difference]: Without dead ends: 991 [2022-12-13 21:47:25,750 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 202 GetRequests, 167 SyntacticMatches, 8 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 203 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-12-13 21:47:25,751 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 263 mSDsluCounter, 471 mSDsCounter, 0 mSdLazyCounter, 529 mSolverCounterSat, 89 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 269 SdHoareTripleChecker+Valid, 571 SdHoareTripleChecker+Invalid, 618 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 89 IncrementalHoareTripleChecker+Valid, 529 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:25,751 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [269 Valid, 571 Invalid, 618 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [89 Valid, 529 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-12-13 21:47:25,752 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 991 states. [2022-12-13 21:47:25,795 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 991 to 862. [2022-12-13 21:47:25,796 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 862 states, 672 states have (on average 1.244047619047619) internal successors, (836), 725 states have internal predecessors, (836), 95 states have call successors, (95), 83 states have call predecessors, (95), 94 states have return successors, (198), 87 states have call predecessors, (198), 95 states have call successors, (198) [2022-12-13 21:47:25,799 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 862 states to 862 states and 1129 transitions. [2022-12-13 21:47:25,799 INFO L78 Accepts]: Start accepts. Automaton has 862 states and 1129 transitions. Word has length 80 [2022-12-13 21:47:25,799 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:25,799 INFO L495 AbstractCegarLoop]: Abstraction has 862 states and 1129 transitions. [2022-12-13 21:47:25,800 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 8.333333333333334) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-12-13 21:47:25,800 INFO L276 IsEmpty]: Start isEmpty. Operand 862 states and 1129 transitions. [2022-12-13 21:47:25,801 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 115 [2022-12-13 21:47:25,802 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:25,802 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:25,807 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-12-13 21:47:26,002 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-12-13 21:47:26,003 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:26,003 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:26,003 INFO L85 PathProgramCache]: Analyzing trace with hash 1682583131, now seen corresponding path program 2 times [2022-12-13 21:47:26,003 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:26,003 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1068990996] [2022-12-13 21:47:26,003 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:26,003 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:26,026 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,105 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:26,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,112 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-12-13 21:47:26,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,123 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-12-13 21:47:26,126 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,135 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 54 [2022-12-13 21:47:26,139 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,219 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-12-13 21:47:26,220 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,222 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-12-13 21:47:26,223 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,224 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2022-12-13 21:47:26,225 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,226 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-12-13 21:47:26,227 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:26,229 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 51 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-12-13 21:47:26,229 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:26,229 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1068990996] [2022-12-13 21:47:26,229 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1068990996] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-13 21:47:26,229 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [745711853] [2022-12-13 21:47:26,229 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-12-13 21:47:26,229 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-13 21:47:26,229 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 [2022-12-13 21:47:26,230 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-13 21:47:26,231 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-12-13 21:47:26,312 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-12-13 21:47:26,312 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-12-13 21:47:26,314 INFO L263 TraceCheckSpWp]: Trace formula consists of 381 conjuncts, 10 conjunts are in the unsatisfiable core [2022-12-13 21:47:26,317 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-13 21:47:26,412 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 62 proven. 0 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-12-13 21:47:26,413 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-12-13 21:47:26,413 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [745711853] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:26,413 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-12-13 21:47:26,413 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2022-12-13 21:47:26,413 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [484676588] [2022-12-13 21:47:26,413 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:26,414 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-12-13 21:47:26,414 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:26,414 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-12-13 21:47:26,415 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2022-12-13 21:47:26,415 INFO L87 Difference]: Start difference. First operand 862 states and 1129 transitions. Second operand has 6 states, 6 states have (on average 14.833333333333334) internal successors, (89), 6 states have internal predecessors, (89), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-12-13 21:47:26,727 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:26,727 INFO L93 Difference]: Finished difference Result 2363 states and 3215 transitions. [2022-12-13 21:47:26,728 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-12-13 21:47:26,728 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 14.833333333333334) internal successors, (89), 6 states have internal predecessors, (89), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 114 [2022-12-13 21:47:26,728 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:26,736 INFO L225 Difference]: With dead ends: 2363 [2022-12-13 21:47:26,736 INFO L226 Difference]: Without dead ends: 1613 [2022-12-13 21:47:26,740 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 146 GetRequests, 127 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 45 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2022-12-13 21:47:26,741 INFO L413 NwaCegarLoop]: 159 mSDtfsCounter, 234 mSDsluCounter, 384 mSDsCounter, 0 mSdLazyCounter, 132 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 234 SdHoareTripleChecker+Valid, 543 SdHoareTripleChecker+Invalid, 167 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 132 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:26,741 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [234 Valid, 543 Invalid, 167 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 132 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-13 21:47:26,743 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1613 states. [2022-12-13 21:47:26,848 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1613 to 1493. [2022-12-13 21:47:26,850 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1493 states, 1166 states have (on average 1.2435677530017153) internal successors, (1450), 1246 states have internal predecessors, (1450), 166 states have call successors, (166), 148 states have call predecessors, (166), 160 states have return successors, (304), 150 states have call predecessors, (304), 166 states have call successors, (304) [2022-12-13 21:47:26,858 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1493 states to 1493 states and 1920 transitions. [2022-12-13 21:47:26,858 INFO L78 Accepts]: Start accepts. Automaton has 1493 states and 1920 transitions. Word has length 114 [2022-12-13 21:47:26,859 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:26,859 INFO L495 AbstractCegarLoop]: Abstraction has 1493 states and 1920 transitions. [2022-12-13 21:47:26,859 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 14.833333333333334) internal successors, (89), 6 states have internal predecessors, (89), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-12-13 21:47:26,859 INFO L276 IsEmpty]: Start isEmpty. Operand 1493 states and 1920 transitions. [2022-12-13 21:47:26,863 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 115 [2022-12-13 21:47:26,864 INFO L187 NwaCegarLoop]: Found error trace [2022-12-13 21:47:26,864 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:26,868 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-12-13 21:47:27,064 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-13 21:47:27,065 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-13 21:47:27,065 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-13 21:47:27,065 INFO L85 PathProgramCache]: Analyzing trace with hash 2126483805, now seen corresponding path program 1 times [2022-12-13 21:47:27,065 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-12-13 21:47:27,065 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [381873588] [2022-12-13 21:47:27,065 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-13 21:47:27,065 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-13 21:47:27,074 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,113 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-12-13 21:47:27,113 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,118 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-12-13 21:47:27,120 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,126 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-12-13 21:47:27,128 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,131 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 54 [2022-12-13 21:47:27,135 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,158 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-12-13 21:47:27,159 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,160 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-12-13 21:47:27,161 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,162 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2022-12-13 21:47:27,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,163 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-12-13 21:47:27,163 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-13 21:47:27,164 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 42 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2022-12-13 21:47:27,164 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-12-13 21:47:27,164 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [381873588] [2022-12-13 21:47:27,164 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [381873588] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-13 21:47:27,165 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-13 21:47:27,165 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-12-13 21:47:27,165 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [513444009] [2022-12-13 21:47:27,165 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-13 21:47:27,165 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-12-13 21:47:27,165 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-12-13 21:47:27,166 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-12-13 21:47:27,166 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-12-13 21:47:27,166 INFO L87 Difference]: Start difference. First operand 1493 states and 1920 transitions. Second operand has 8 states, 8 states have (on average 10.0) internal successors, (80), 5 states have internal predecessors, (80), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-12-13 21:47:27,383 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-13 21:47:27,383 INFO L93 Difference]: Finished difference Result 2099 states and 2662 transitions. [2022-12-13 21:47:27,383 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-12-13 21:47:27,383 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 10.0) internal successors, (80), 5 states have internal predecessors, (80), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 114 [2022-12-13 21:47:27,384 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-13 21:47:27,384 INFO L225 Difference]: With dead ends: 2099 [2022-12-13 21:47:27,384 INFO L226 Difference]: Without dead ends: 0 [2022-12-13 21:47:27,389 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2022-12-13 21:47:27,390 INFO L413 NwaCegarLoop]: 61 mSDtfsCounter, 157 mSDsluCounter, 219 mSDsCounter, 0 mSdLazyCounter, 235 mSolverCounterSat, 37 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 159 SdHoareTripleChecker+Valid, 280 SdHoareTripleChecker+Invalid, 272 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 37 IncrementalHoareTripleChecker+Valid, 235 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-13 21:47:27,390 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [159 Valid, 280 Invalid, 272 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [37 Valid, 235 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-13 21:47:27,390 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-12-13 21:47:27,390 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-12-13 21:47:27,390 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-13 21:47:27,391 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-12-13 21:47:27,391 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 114 [2022-12-13 21:47:27,391 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-13 21:47:27,391 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-12-13 21:47:27,391 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 10.0) internal successors, (80), 5 states have internal predecessors, (80), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-12-13 21:47:27,391 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-12-13 21:47:27,391 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-12-13 21:47:27,394 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-12-13 21:47:27,394 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2022-12-13 21:47:27,395 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-12-13 21:47:30,304 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 309 316) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 309 316) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 309 316) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 224 230) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 224 230) the Hoare annotation is: true [2022-12-13 21:47:30,305 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 549 560) the Hoare annotation is: true [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point L553-1(lines 549 560) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 549 560) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point L449(line 449) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 428 457) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L899 garLoopResultBuilder]: For program point L442(lines 442 446) no Hoare annotation was computed. [2022-12-13 21:47:30,305 INFO L902 garLoopResultBuilder]: At program point L442-1(lines 442 446) the Hoare annotation is: true [2022-12-13 21:47:30,306 INFO L899 garLoopResultBuilder]: For program point L439(line 439) no Hoare annotation was computed. [2022-12-13 21:47:30,306 INFO L902 garLoopResultBuilder]: At program point L438-2(lines 438 452) the Hoare annotation is: true [2022-12-13 21:47:30,306 INFO L902 garLoopResultBuilder]: At program point L434(line 434) the Hoare annotation is: true [2022-12-13 21:47:30,306 INFO L899 garLoopResultBuilder]: For program point L434-1(line 434) no Hoare annotation was computed. [2022-12-13 21:47:30,306 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 428 457) the Hoare annotation is: true [2022-12-13 21:47:30,306 INFO L902 garLoopResultBuilder]: At program point L453(lines 428 457) the Hoare annotation is: true [2022-12-13 21:47:30,306 INFO L899 garLoopResultBuilder]: For program point L630(line 630) no Hoare annotation was computed. [2022-12-13 21:47:30,306 INFO L895 garLoopResultBuilder]: At program point isLowWaterSensorDry_returnLabel#1(lines 616 624) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,306 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 200 223) no Hoare annotation was computed. [2022-12-13 21:47:30,307 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 593 601) the Hoare annotation is: (let ((.cse0 (<= 2 ~waterLevel~0)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse4 (= 0 ~systemActive~0))) (let ((.cse3 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (= ~pumpRunning~0 0)) (.cse7 (and .cse0 .cse8 .cse1 (not .cse4))) (.cse6 (not (= |old(~pumpRunning~0)| 0)))) (and (or (and .cse0 .cse1) (and .cse2 (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 ~waterLevel~0) .cse3) .cse4 .cse5) (or .cse6 .cse7 .cse4 .cse5) (or .cse6 .cse3 .cse5) (or .cse6 (and .cse2 .cse8) .cse7 (not (<= 1 |old(~waterLevel~0)|))) (or .cse6 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-12-13 21:47:30,307 INFO L895 garLoopResultBuilder]: At program point L272(line 272) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,307 INFO L895 garLoopResultBuilder]: At program point L268(line 268) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,307 INFO L899 garLoopResultBuilder]: For program point L103(lines 103 109) no Hoare annotation was computed. [2022-12-13 21:47:30,307 INFO L899 garLoopResultBuilder]: For program point L99(lines 99 112) no Hoare annotation was computed. [2022-12-13 21:47:30,307 INFO L895 garLoopResultBuilder]: At program point L99-1(lines 91 115) the Hoare annotation is: (let ((.cse8 (<= 2 ~waterLevel~0)) (.cse9 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~0#1|)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse10 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse8 .cse9 .cse6 .cse10 (not .cse2))) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse7 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~0#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~0#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 .cse1 .cse2 .cse3) (or .cse0 (not (<= 1 |old(~waterLevel~0)|)) (and .cse4 .cse5 .cse6 .cse7) .cse1) (or (and .cse8 .cse9 .cse10) (and .cse4 (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 ~waterLevel~0) .cse5 .cse7) .cse2 .cse3)))) [2022-12-13 21:47:30,308 INFO L895 garLoopResultBuilder]: At program point L277(line 277) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-12-13 21:47:30,308 INFO L895 garLoopResultBuilder]: At program point L277-1(lines 258 282) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or (and .cse0 (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 ~waterLevel~0)) .cse3 .cse4 (not (<= 2 |old(~waterLevel~0)|))))) [2022-12-13 21:47:30,308 INFO L899 garLoopResultBuilder]: For program point L211-1(lines 211 217) no Hoare annotation was computed. [2022-12-13 21:47:30,308 INFO L899 garLoopResultBuilder]: For program point L529(lines 529 533) no Hoare annotation was computed. [2022-12-13 21:47:30,308 INFO L899 garLoopResultBuilder]: For program point L401(lines 401 405) no Hoare annotation was computed. [2022-12-13 21:47:30,308 INFO L895 garLoopResultBuilder]: At program point L529-2(lines 525 536) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,308 INFO L899 garLoopResultBuilder]: For program point L401-2(lines 401 405) no Hoare annotation was computed. [2022-12-13 21:47:30,308 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 626 633) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,309 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 200 223) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-12-13 21:47:30,309 INFO L895 garLoopResultBuilder]: At program point isLowWaterLevel_returnLabel#1(lines 392 410) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point L204-1(lines 203 222) no Hoare annotation was computed. [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 200 223) no Hoare annotation was computed. [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point L266(lines 266 274) no Hoare annotation was computed. [2022-12-13 21:47:30,309 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 328 336) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 630) no Hoare annotation was computed. [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point L262(lines 262 279) no Hoare annotation was computed. [2022-12-13 21:47:30,309 INFO L899 garLoopResultBuilder]: For program point L415(lines 415 421) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point L415-1(lines 415 421) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L895 garLoopResultBuilder]: At program point L180(lines 131 181) the Hoare annotation is: false [2022-12-13 21:47:30,310 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 489 498) the Hoare annotation is: true [2022-12-13 21:47:30,310 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 64 70) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-12-13 21:47:30,310 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 499 521) the Hoare annotation is: true [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point L168(lines 168 174) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L895 garLoopResultBuilder]: At program point L168-2(lines 162 175) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point L152(lines 152 158) no Hoare annotation was computed. [2022-12-13 21:47:30,310 INFO L899 garLoopResultBuilder]: For program point L152-1(lines 152 158) no Hoare annotation was computed. [2022-12-13 21:47:30,311 INFO L895 garLoopResultBuilder]: At program point L177(lines 132 179) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-12-13 21:47:30,311 INFO L895 garLoopResultBuilder]: At program point L144(line 144) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-12-13 21:47:30,311 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 482 488) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0)) [2022-12-13 21:47:30,311 INFO L895 garLoopResultBuilder]: At program point L417(line 417) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~7#1| 1) (= |ULTIMATE.start_valid_product_#res#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-12-13 21:47:30,311 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-12-13 21:47:30,311 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2022-12-13 21:47:30,311 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 71 77) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-12-13 21:47:30,311 INFO L899 garLoopResultBuilder]: For program point L133(lines 132 179) no Hoare annotation was computed. [2022-12-13 21:47:30,311 INFO L899 garLoopResultBuilder]: For program point L162(lines 162 175) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L509(lines 509 516) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L509-2(lines 509 516) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L895 garLoopResultBuilder]: At program point L154(line 154) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse4 (= ~waterLevel~0 1)) (and .cse0 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))))) [2022-12-13 21:47:30,312 INFO L902 garLoopResultBuilder]: At program point L183(lines 122 187) the Hoare annotation is: true [2022-12-13 21:47:30,312 INFO L895 garLoopResultBuilder]: At program point stopSystem_returnLabel#1(lines 411 425) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~7#1| 1)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1)))) [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L142(lines 142 148) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L142-1(lines 142 148) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 78 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L134(lines 134 138) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L382(lines 382 386) no Hoare annotation was computed. [2022-12-13 21:47:30,312 INFO L899 garLoopResultBuilder]: For program point L382-2(lines 382 386) no Hoare annotation was computed. [2022-12-13 21:47:30,313 INFO L895 garLoopResultBuilder]: At program point L246(line 246) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~5#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse0 .cse1) (or .cse0 (not (<= 1 ~waterLevel~0)) .cse1 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0))))) [2022-12-13 21:47:30,313 INFO L899 garLoopResultBuilder]: For program point L240(lines 240 248) no Hoare annotation was computed. [2022-12-13 21:47:30,313 INFO L899 garLoopResultBuilder]: For program point L236(lines 236 253) no Hoare annotation was computed. [2022-12-13 21:47:30,313 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 232 256) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-12-13 21:47:30,313 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 602 615) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0 .cse1) (or .cse0 (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) .cse1))) [2022-12-13 21:47:30,313 INFO L899 garLoopResultBuilder]: For program point L606(lines 606 612) no Hoare annotation was computed. [2022-12-13 21:47:30,313 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 373 391) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) .cse2) (or (not (= ~waterLevel~0 1)) .cse0 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~5#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse2))) [2022-12-13 21:47:30,313 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 232 256) no Hoare annotation was computed. [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point L251(line 251) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-12-13 21:47:30,314 INFO L899 garLoopResultBuilder]: For program point L251-1(lines 232 256) no Hoare annotation was computed. [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point isMethaneLevelCritical_returnLabel#1(lines 561 569) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-12-13 21:47:30,314 INFO L899 garLoopResultBuilder]: For program point L299(lines 299 305) no Hoare annotation was computed. [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point isMethaneAlarm_returnLabel#1(lines 317 327) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point L299-2(lines 292 308) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point activatePump__wrappee__lowWaterSensor_returnLabel#1(lines 283 290) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-12-13 21:47:30,314 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 537 548) no Hoare annotation was computed. [2022-12-13 21:47:30,314 INFO L899 garLoopResultBuilder]: For program point L541-1(lines 537 548) no Hoare annotation was computed. [2022-12-13 21:47:30,314 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 537 548) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-12-13 21:47:30,317 INFO L445 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-13 21:47:30,319 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-12-13 21:47:30,334 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 13.12 09:47:30 BoogieIcfgContainer [2022-12-13 21:47:30,334 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-12-13 21:47:30,335 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-12-13 21:47:30,335 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-12-13 21:47:30,335 INFO L275 PluginConnector]: Witness Printer initialized [2022-12-13 21:47:30,335 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.12 09:47:22" (3/4) ... [2022-12-13 21:47:30,337 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-12-13 21:47:30,342 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-12-13 21:47:30,347 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 26 nodes and edges [2022-12-13 21:47:30,347 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 8 nodes and edges [2022-12-13 21:47:30,347 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 4 nodes and edges [2022-12-13 21:47:30,347 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-12-13 21:47:30,348 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-12-13 21:47:30,365 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-12-13 21:47:30,365 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive [2022-12-13 21:47:30,365 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1)) || ((((tmp == 1 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) [2022-12-13 21:47:30,365 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,366 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,366 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-12-13 21:47:30,366 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1) [2022-12-13 21:47:30,366 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1)) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || (((pumpRunning == 0 && 1 <= \result) && \old(waterLevel) == waterLevel) && 1 <= tmp)) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive)))) && (((((2 <= waterLevel && 2 <= tmp) && 2 <= \result) || ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,366 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,367 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || 1 <= \result) || !(\old(pumpRunning) == 0)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-12-13 21:47:30,367 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,367 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && tmp == 0) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,367 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && pumpRunning == 0) && tmp___0 == 0) && 1 <= tmp) && \result == 0)) || 0 == systemActive) [2022-12-13 21:47:30,367 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-12-13 21:47:30,368 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-12-13 21:47:30,368 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-12-13 21:47:30,368 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-12-13 21:47:30,368 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-12-13 21:47:30,383 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/witness.graphml [2022-12-13 21:47:30,384 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-12-13 21:47:30,384 INFO L158 Benchmark]: Toolchain (without parser) took 9003.47ms. Allocated memory was 142.6MB in the beginning and 172.0MB in the end (delta: 29.4MB). Free memory was 105.4MB in the beginning and 123.8MB in the end (delta: -18.4MB). Peak memory consumption was 11.9MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,384 INFO L158 Benchmark]: CDTParser took 0.13ms. Allocated memory is still 142.6MB. Free memory is still 108.9MB. There was no memory consumed. Max. memory is 16.1GB. [2022-12-13 21:47:30,384 INFO L158 Benchmark]: CACSL2BoogieTranslator took 291.11ms. Allocated memory is still 142.6MB. Free memory was 105.4MB in the beginning and 86.6MB in the end (delta: 18.8MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,385 INFO L158 Benchmark]: Boogie Procedure Inliner took 32.83ms. Allocated memory is still 142.6MB. Free memory was 86.6MB in the beginning and 84.4MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,385 INFO L158 Benchmark]: Boogie Preprocessor took 18.78ms. Allocated memory is still 142.6MB. Free memory was 84.4MB in the beginning and 82.8MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,385 INFO L158 Benchmark]: RCFGBuilder took 372.85ms. Allocated memory is still 142.6MB. Free memory was 82.4MB in the beginning and 66.1MB in the end (delta: 16.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,385 INFO L158 Benchmark]: TraceAbstraction took 8233.42ms. Allocated memory was 142.6MB in the beginning and 172.0MB in the end (delta: 29.4MB). Free memory was 65.1MB in the beginning and 129.0MB in the end (delta: -63.9MB). Peak memory consumption was 58.8MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,385 INFO L158 Benchmark]: Witness Printer took 48.94ms. Allocated memory is still 172.0MB. Free memory was 129.0MB in the beginning and 123.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-12-13 21:47:30,387 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.13ms. Allocated memory is still 142.6MB. Free memory is still 108.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 291.11ms. Allocated memory is still 142.6MB. Free memory was 105.4MB in the beginning and 86.6MB in the end (delta: 18.8MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 32.83ms. Allocated memory is still 142.6MB. Free memory was 86.6MB in the beginning and 84.4MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 18.78ms. Allocated memory is still 142.6MB. Free memory was 84.4MB in the beginning and 82.8MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 372.85ms. Allocated memory is still 142.6MB. Free memory was 82.4MB in the beginning and 66.1MB in the end (delta: 16.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 8233.42ms. Allocated memory was 142.6MB in the beginning and 172.0MB in the end (delta: 29.4MB). Free memory was 65.1MB in the beginning and 129.0MB in the end (delta: -63.9MB). Peak memory consumption was 58.8MB. Max. memory is 16.1GB. * Witness Printer took 48.94ms. Allocated memory is still 172.0MB. Free memory was 129.0MB in the beginning and 123.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 630]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 93 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 8.2s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 2.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1801 SdHoareTripleChecker+Valid, 1.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1783 mSDsluCounter, 4116 SdHoareTripleChecker+Invalid, 1.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2958 mSDsCounter, 392 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2122 IncrementalHoareTripleChecker+Invalid, 2514 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 392 mSolverCounterUnsat, 1158 mSDtfsCounter, 2122 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 470 GetRequests, 344 SyntacticMatches, 11 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 344 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1493occurred in iteration=11, InterpolantAutomatonStates: 112, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 12 MinimizatonAttempts, 484 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 2690 PreInvPairs, 2995 NumberOfFragments, 1140 HoareAnnotationTreeSize, 2690 FomulaSimplifications, 3649 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 44 FomulaSimplificationsInter, 23497 FormulaSimplificationTreeSizeReductionInter, 2.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 793 NumberOfCodeBlocks, 793 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 858 ConstructedInterpolants, 0 QuantifiedInterpolants, 1642 SizeOfPredicates, 8 NumberOfNonLiveVariables, 679 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 15 InterpolantComputations, 11 PerfectInterpolantSequences, 252/282 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 131]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 482]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive - InvariantResult [Line: 258]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 283]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && tmp == 0) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 328]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 91]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1)) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || (((pumpRunning == 0 && 1 <= \result) && \old(waterLevel) == waterLevel) && 1 <= tmp)) || ((((2 <= waterLevel && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive)))) && (((((2 <= waterLevel && 2 <= tmp) && 2 <= \result) || ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 428]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 602]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || 1 <= \result) || !(\old(pumpRunning) == 0)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 616]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 438]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 373]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && pumpRunning == 0) && tmp___0 == 0) && 1 <= tmp) && \result == 0)) || 0 == systemActive) - InvariantResult [Line: 489]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 411]: Loop Invariant Derived loop invariant: ((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 292]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 626]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 132]: Loop Invariant Derived loop invariant: (((((tmp == 1 && pumpRunning == 0) && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) || ((((tmp == 1 && pumpRunning == 0) && \result == 1) && splverifierCounter == 0) && waterLevel == 1)) || ((((tmp == 1 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 525]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 593]: Loop Invariant Derived loop invariant: (((((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && 1 <= tmp___0) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 561]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 499]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 122]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-12-13 21:47:30,409 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_75aacd4c-deea-4aee-824d-77d9dca3eb59/bin/uautomizer-uyxdKDjOR8/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE