./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 5a0a9a5f1521df25ea0ff390c35c7186e45318cd30c225704d83030e156744fb --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 03:45:48,831 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 03:45:48,834 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 03:45:48,888 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 03:45:48,889 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 03:45:48,893 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 03:45:48,895 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 03:45:48,901 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 03:45:48,904 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 03:45:48,910 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 03:45:48,911 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 03:45:48,914 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 03:45:48,915 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 03:45:48,918 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 03:45:48,920 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 03:45:48,923 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 03:45:48,924 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 03:45:48,926 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 03:45:48,927 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 03:45:48,935 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 03:45:48,937 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 03:45:48,938 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 03:45:48,942 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 03:45:48,944 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 03:45:48,953 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 03:45:48,954 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 03:45:48,954 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 03:45:48,956 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 03:45:48,957 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 03:45:48,958 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 03:45:48,959 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 03:45:48,960 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 03:45:48,962 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 03:45:48,966 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 03:45:48,967 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 03:45:48,967 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 03:45:48,968 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 03:45:48,969 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 03:45:48,969 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 03:45:48,970 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 03:45:48,971 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 03:45:48,972 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 03:45:49,013 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 03:45:49,014 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 03:45:49,015 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 03:45:49,015 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 03:45:49,016 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 03:45:49,016 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 03:45:49,016 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 03:45:49,017 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 03:45:49,017 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 03:45:49,017 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 03:45:49,018 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 03:45:49,019 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 03:45:49,019 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 03:45:49,019 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 03:45:49,020 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 03:45:49,020 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 03:45:49,020 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 03:45:49,020 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 03:45:49,021 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 03:45:49,021 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 03:45:49,022 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 03:45:49,022 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 03:45:49,022 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 03:45:49,024 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 03:45:49,024 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 03:45:49,024 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 03:45:49,025 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 03:45:49,025 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 03:45:49,025 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 03:45:49,025 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 03:45:49,026 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 03:45:49,026 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 03:45:49,026 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:45:49,027 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 03:45:49,027 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 03:45:49,027 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 03:45:49,027 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 03:45:49,028 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 03:45:49,028 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 03:45:49,028 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 03:45:49,028 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 03:45:49,029 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 5a0a9a5f1521df25ea0ff390c35c7186e45318cd30c225704d83030e156744fb [2022-11-03 03:45:49,347 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 03:45:49,378 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 03:45:49,380 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 03:45:49,382 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 03:45:49,383 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 03:45:49,384 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c [2022-11-03 03:45:49,462 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/data/7b459027e/d372e490ad4643188c6ea22a0e08a145/FLAGcedf2ace0 [2022-11-03 03:45:49,984 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 03:45:49,985 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c [2022-11-03 03:45:49,995 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/data/7b459027e/d372e490ad4643188c6ea22a0e08a145/FLAGcedf2ace0 [2022-11-03 03:45:50,314 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/data/7b459027e/d372e490ad4643188c6ea22a0e08a145 [2022-11-03 03:45:50,317 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 03:45:50,318 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 03:45:50,324 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 03:45:50,325 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 03:45:50,328 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 03:45:50,329 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:50,331 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@5d0db630 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50, skipping insertion in model container [2022-11-03 03:45:50,331 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:50,339 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 03:45:50,405 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 03:45:50,692 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c[3645,3658] [2022-11-03 03:45:50,827 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:45:50,841 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 03:45:50,860 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c[3645,3658] [2022-11-03 03:45:50,903 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:45:50,919 INFO L208 MainTranslator]: Completed translation [2022-11-03 03:45:50,920 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50 WrapperNode [2022-11-03 03:45:50,920 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 03:45:50,921 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 03:45:50,921 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 03:45:50,921 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 03:45:50,929 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:50,943 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:50,978 INFO L138 Inliner]: procedures = 57, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 271 [2022-11-03 03:45:50,979 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 03:45:50,980 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 03:45:50,984 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 03:45:50,984 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 03:45:50,996 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:50,996 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,000 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,001 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,007 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,013 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,015 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,016 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,019 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 03:45:51,020 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 03:45:51,020 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 03:45:51,020 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 03:45:51,025 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (1/1) ... [2022-11-03 03:45:51,045 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:45:51,057 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:45:51,069 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 03:45:51,087 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 03:45:51,128 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 03:45:51,128 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 03:45:51,128 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 03:45:51,129 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 03:45:51,129 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 03:45:51,129 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 03:45:51,129 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 03:45:51,130 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-03 03:45:51,130 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-03 03:45:51,130 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:45:51,130 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:45:51,130 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 03:45:51,130 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 03:45:51,131 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-03 03:45:51,131 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-03 03:45:51,131 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 03:45:51,131 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 03:45:51,131 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 03:45:51,131 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 03:45:51,132 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 03:45:51,226 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 03:45:51,228 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 03:45:51,619 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 03:45:51,737 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 03:45:51,737 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 03:45:51,740 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:51 BoogieIcfgContainer [2022-11-03 03:45:51,740 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 03:45:51,743 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 03:45:51,743 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 03:45:51,746 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 03:45:51,747 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 03:45:50" (1/3) ... [2022-11-03 03:45:51,748 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@518e7b58 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:45:51, skipping insertion in model container [2022-11-03 03:45:51,748 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:50" (2/3) ... [2022-11-03 03:45:51,748 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@518e7b58 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:45:51, skipping insertion in model container [2022-11-03 03:45:51,748 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:51" (3/3) ... [2022-11-03 03:45:51,750 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product59.cil.c [2022-11-03 03:45:51,769 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 03:45:51,769 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 03:45:51,831 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 03:45:51,847 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@2dcb9ffc, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 03:45:51,847 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 03:45:51,851 INFO L276 IsEmpty]: Start isEmpty. Operand has 65 states, 41 states have (on average 1.4390243902439024) internal successors, (59), 50 states have internal predecessors, (59), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-03 03:45:51,864 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 17 [2022-11-03 03:45:51,865 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:51,865 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:51,866 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:51,874 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:51,875 INFO L85 PathProgramCache]: Analyzing trace with hash -1746687220, now seen corresponding path program 1 times [2022-11-03 03:45:51,884 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:51,885 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [121956274] [2022-11-03 03:45:51,885 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:51,886 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:52,055 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:52,180 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:52,184 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:52,184 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [121956274] [2022-11-03 03:45:52,185 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [121956274] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:52,185 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:52,185 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 03:45:52,187 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1157127890] [2022-11-03 03:45:52,187 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:52,192 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 03:45:52,193 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:52,230 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 03:45:52,231 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:45:52,234 INFO L87 Difference]: Start difference. First operand has 65 states, 41 states have (on average 1.4390243902439024) internal successors, (59), 50 states have internal predecessors, (59), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:52,307 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:52,308 INFO L93 Difference]: Finished difference Result 128 states and 175 transitions. [2022-11-03 03:45:52,309 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 03:45:52,311 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 16 [2022-11-03 03:45:52,311 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:52,326 INFO L225 Difference]: With dead ends: 128 [2022-11-03 03:45:52,326 INFO L226 Difference]: Without dead ends: 60 [2022-11-03 03:45:52,331 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:45:52,335 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 67 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:52,336 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 67 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:45:52,353 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 60 states. [2022-11-03 03:45:52,388 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 60 to 60. [2022-11-03 03:45:52,390 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 60 states, 38 states have (on average 1.3421052631578947) internal successors, (51), 46 states have internal predecessors, (51), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-03 03:45:52,397 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 60 states to 60 states and 78 transitions. [2022-11-03 03:45:52,399 INFO L78 Accepts]: Start accepts. Automaton has 60 states and 78 transitions. Word has length 16 [2022-11-03 03:45:52,399 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:52,400 INFO L495 AbstractCegarLoop]: Abstraction has 60 states and 78 transitions. [2022-11-03 03:45:52,400 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:52,400 INFO L276 IsEmpty]: Start isEmpty. Operand 60 states and 78 transitions. [2022-11-03 03:45:52,402 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 18 [2022-11-03 03:45:52,402 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:52,402 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:52,403 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 03:45:52,403 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:52,403 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:52,404 INFO L85 PathProgramCache]: Analyzing trace with hash -1438964340, now seen corresponding path program 1 times [2022-11-03 03:45:52,404 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:52,404 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [239712391] [2022-11-03 03:45:52,405 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:52,405 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:52,437 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:52,549 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:52,549 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:52,550 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [239712391] [2022-11-03 03:45:52,551 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [239712391] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:52,551 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:52,551 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:45:52,552 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1513362687] [2022-11-03 03:45:52,552 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:52,553 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:45:52,554 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:52,555 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:45:52,558 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:45:52,559 INFO L87 Difference]: Start difference. First operand 60 states and 78 transitions. Second operand has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:52,637 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:52,637 INFO L93 Difference]: Finished difference Result 92 states and 118 transitions. [2022-11-03 03:45:52,638 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:45:52,639 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 17 [2022-11-03 03:45:52,639 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:52,643 INFO L225 Difference]: With dead ends: 92 [2022-11-03 03:45:52,644 INFO L226 Difference]: Without dead ends: 52 [2022-11-03 03:45:52,649 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:45:52,650 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 14 mSDsluCounter, 47 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 89 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:52,651 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 89 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:45:52,654 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 52 states. [2022-11-03 03:45:52,664 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 52 to 52. [2022-11-03 03:45:52,666 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 52 states, 33 states have (on average 1.3636363636363635) internal successors, (45), 41 states have internal predecessors, (45), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-03 03:45:52,667 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 52 states to 52 states and 67 transitions. [2022-11-03 03:45:52,667 INFO L78 Accepts]: Start accepts. Automaton has 52 states and 67 transitions. Word has length 17 [2022-11-03 03:45:52,667 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:52,668 INFO L495 AbstractCegarLoop]: Abstraction has 52 states and 67 transitions. [2022-11-03 03:45:52,668 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:52,668 INFO L276 IsEmpty]: Start isEmpty. Operand 52 states and 67 transitions. [2022-11-03 03:45:52,669 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-03 03:45:52,669 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:52,670 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:52,670 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 03:45:52,670 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:52,671 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:52,671 INFO L85 PathProgramCache]: Analyzing trace with hash -813556764, now seen corresponding path program 1 times [2022-11-03 03:45:52,671 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:52,671 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [102120348] [2022-11-03 03:45:52,672 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:52,672 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:52,697 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:52,810 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:52,810 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:52,810 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [102120348] [2022-11-03 03:45:52,811 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [102120348] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:52,811 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:52,812 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:45:52,813 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [967646465] [2022-11-03 03:45:52,813 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:52,813 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:45:52,814 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:52,815 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:45:52,815 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:45:52,816 INFO L87 Difference]: Start difference. First operand 52 states and 67 transitions. Second operand has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:53,013 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:53,014 INFO L93 Difference]: Finished difference Result 149 states and 198 transitions. [2022-11-03 03:45:53,014 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:45:53,015 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 20 [2022-11-03 03:45:53,015 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:53,016 INFO L225 Difference]: With dead ends: 149 [2022-11-03 03:45:53,016 INFO L226 Difference]: Without dead ends: 99 [2022-11-03 03:45:53,017 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 03:45:53,018 INFO L413 NwaCegarLoop]: 65 mSDtfsCounter, 81 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 73 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 81 SdHoareTripleChecker+Valid, 148 SdHoareTripleChecker+Invalid, 82 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 73 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:53,019 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [81 Valid, 148 Invalid, 82 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 73 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:45:53,020 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 99 states. [2022-11-03 03:45:53,033 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 99 to 82. [2022-11-03 03:45:53,033 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 82 states, 53 states have (on average 1.3584905660377358) internal successors, (72), 64 states have internal predecessors, (72), 16 states have call successors, (16), 12 states have call predecessors, (16), 12 states have return successors, (17), 12 states have call predecessors, (17), 16 states have call successors, (17) [2022-11-03 03:45:53,034 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 82 states to 82 states and 105 transitions. [2022-11-03 03:45:53,035 INFO L78 Accepts]: Start accepts. Automaton has 82 states and 105 transitions. Word has length 20 [2022-11-03 03:45:53,035 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:53,035 INFO L495 AbstractCegarLoop]: Abstraction has 82 states and 105 transitions. [2022-11-03 03:45:53,035 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:53,036 INFO L276 IsEmpty]: Start isEmpty. Operand 82 states and 105 transitions. [2022-11-03 03:45:53,036 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2022-11-03 03:45:53,037 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:53,037 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:53,037 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 03:45:53,037 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:53,038 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:53,038 INFO L85 PathProgramCache]: Analyzing trace with hash -616885384, now seen corresponding path program 1 times [2022-11-03 03:45:53,038 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:53,038 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1149307113] [2022-11-03 03:45:53,038 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:53,039 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:53,053 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:53,193 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:53,193 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:53,194 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1149307113] [2022-11-03 03:45:53,194 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1149307113] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:53,194 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:53,194 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:45:53,194 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [424692522] [2022-11-03 03:45:53,195 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:53,195 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:45:53,195 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:53,196 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:45:53,196 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:45:53,196 INFO L87 Difference]: Start difference. First operand 82 states and 105 transitions. Second operand has 6 states, 5 states have (on average 4.0) internal successors, (20), 4 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:53,357 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:53,357 INFO L93 Difference]: Finished difference Result 240 states and 314 transitions. [2022-11-03 03:45:53,357 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 03:45:53,358 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.0) internal successors, (20), 4 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2022-11-03 03:45:53,358 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:53,360 INFO L225 Difference]: With dead ends: 240 [2022-11-03 03:45:53,360 INFO L226 Difference]: Without dead ends: 160 [2022-11-03 03:45:53,361 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 03:45:53,362 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 44 mSDsluCounter, 255 mSDsCounter, 0 mSdLazyCounter, 102 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 47 SdHoareTripleChecker+Valid, 273 SdHoareTripleChecker+Invalid, 104 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 102 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:53,363 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [47 Valid, 273 Invalid, 104 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 102 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:45:53,363 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 160 states. [2022-11-03 03:45:53,383 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 160 to 152. [2022-11-03 03:45:53,384 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 152 states, 99 states have (on average 1.3434343434343434) internal successors, (133), 118 states have internal predecessors, (133), 30 states have call successors, (30), 22 states have call predecessors, (30), 22 states have return successors, (32), 22 states have call predecessors, (32), 30 states have call successors, (32) [2022-11-03 03:45:53,386 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 152 states to 152 states and 195 transitions. [2022-11-03 03:45:53,386 INFO L78 Accepts]: Start accepts. Automaton has 152 states and 195 transitions. Word has length 23 [2022-11-03 03:45:53,386 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:53,386 INFO L495 AbstractCegarLoop]: Abstraction has 152 states and 195 transitions. [2022-11-03 03:45:53,387 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.0) internal successors, (20), 4 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:45:53,387 INFO L276 IsEmpty]: Start isEmpty. Operand 152 states and 195 transitions. [2022-11-03 03:45:53,388 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-11-03 03:45:53,388 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:53,389 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:53,389 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 03:45:53,389 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:53,389 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:53,390 INFO L85 PathProgramCache]: Analyzing trace with hash 2140322578, now seen corresponding path program 1 times [2022-11-03 03:45:53,390 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:53,390 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [502553392] [2022-11-03 03:45:53,390 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:53,390 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:53,407 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:53,622 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:53,622 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:53,622 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [502553392] [2022-11-03 03:45:53,622 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [502553392] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:53,622 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:53,623 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:45:53,628 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [30851228] [2022-11-03 03:45:53,629 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:53,630 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:45:53,630 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:53,630 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:45:53,630 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:45:53,631 INFO L87 Difference]: Start difference. First operand 152 states and 195 transitions. Second operand has 4 states, 4 states have (on average 5.25) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:53,749 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:53,750 INFO L93 Difference]: Finished difference Result 368 states and 488 transitions. [2022-11-03 03:45:53,751 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-03 03:45:53,752 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 5.25) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 26 [2022-11-03 03:45:53,752 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:53,760 INFO L225 Difference]: With dead ends: 368 [2022-11-03 03:45:53,760 INFO L226 Difference]: Without dead ends: 218 [2022-11-03 03:45:53,764 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 03:45:53,767 INFO L413 NwaCegarLoop]: 58 mSDtfsCounter, 38 mSDsluCounter, 114 mSDsCounter, 0 mSdLazyCounter, 48 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 156 SdHoareTripleChecker+Invalid, 56 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 48 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:53,768 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [38 Valid, 156 Invalid, 56 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 48 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:45:53,772 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 218 states. [2022-11-03 03:45:53,825 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 218 to 210. [2022-11-03 03:45:53,827 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 210 states, 143 states have (on average 1.2797202797202798) internal successors, (183), 159 states have internal predecessors, (183), 35 states have call successors, (35), 31 states have call predecessors, (35), 31 states have return successors, (47), 33 states have call predecessors, (47), 35 states have call successors, (47) [2022-11-03 03:45:53,829 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 210 states to 210 states and 265 transitions. [2022-11-03 03:45:53,829 INFO L78 Accepts]: Start accepts. Automaton has 210 states and 265 transitions. Word has length 26 [2022-11-03 03:45:53,830 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:53,830 INFO L495 AbstractCegarLoop]: Abstraction has 210 states and 265 transitions. [2022-11-03 03:45:53,830 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 5.25) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:53,831 INFO L276 IsEmpty]: Start isEmpty. Operand 210 states and 265 transitions. [2022-11-03 03:45:53,837 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-03 03:45:53,848 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:53,849 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:53,849 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 03:45:53,851 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:53,852 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:53,852 INFO L85 PathProgramCache]: Analyzing trace with hash -1556478412, now seen corresponding path program 1 times [2022-11-03 03:45:53,852 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:53,853 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2110642502] [2022-11-03 03:45:53,853 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:53,854 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:53,883 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:54,154 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:45:54,155 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:54,155 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2110642502] [2022-11-03 03:45:54,155 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2110642502] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:54,155 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:54,155 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:45:54,156 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [303729469] [2022-11-03 03:45:54,156 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:54,156 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:45:54,156 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:54,157 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:45:54,157 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:45:54,157 INFO L87 Difference]: Start difference. First operand 210 states and 265 transitions. Second operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:45:54,390 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:54,391 INFO L93 Difference]: Finished difference Result 642 states and 821 transitions. [2022-11-03 03:45:54,391 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-03 03:45:54,392 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 35 [2022-11-03 03:45:54,393 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:54,398 INFO L225 Difference]: With dead ends: 642 [2022-11-03 03:45:54,399 INFO L226 Difference]: Without dead ends: 434 [2022-11-03 03:45:54,400 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-03 03:45:54,402 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 135 mSDsluCounter, 114 mSDsCounter, 0 mSdLazyCounter, 98 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 136 SdHoareTripleChecker+Valid, 181 SdHoareTripleChecker+Invalid, 132 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 98 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:54,405 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [136 Valid, 181 Invalid, 132 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 98 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 03:45:54,407 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 434 states. [2022-11-03 03:45:54,464 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 434 to 374. [2022-11-03 03:45:54,465 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 374 states, 263 states have (on average 1.273764258555133) internal successors, (335), 282 states have internal predecessors, (335), 54 states have call successors, (54), 52 states have call predecessors, (54), 56 states have return successors, (72), 54 states have call predecessors, (72), 54 states have call successors, (72) [2022-11-03 03:45:54,468 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 374 states to 374 states and 461 transitions. [2022-11-03 03:45:54,468 INFO L78 Accepts]: Start accepts. Automaton has 374 states and 461 transitions. Word has length 35 [2022-11-03 03:45:54,468 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:54,468 INFO L495 AbstractCegarLoop]: Abstraction has 374 states and 461 transitions. [2022-11-03 03:45:54,469 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:45:54,469 INFO L276 IsEmpty]: Start isEmpty. Operand 374 states and 461 transitions. [2022-11-03 03:45:54,473 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-03 03:45:54,473 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:54,473 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:54,473 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 03:45:54,474 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:54,474 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:54,474 INFO L85 PathProgramCache]: Analyzing trace with hash 615116642, now seen corresponding path program 1 times [2022-11-03 03:45:54,474 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:54,475 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1774887111] [2022-11-03 03:45:54,475 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:54,475 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:54,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:54,801 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 03:45:54,801 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:54,802 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1774887111] [2022-11-03 03:45:54,802 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1774887111] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:45:54,802 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [962773714] [2022-11-03 03:45:54,802 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:54,802 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:45:54,802 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:45:54,808 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:45:54,843 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 03:45:54,952 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:54,956 INFO L263 TraceCheckSpWp]: Trace formula consists of 351 conjuncts, 31 conjunts are in the unsatisfiable core [2022-11-03 03:45:54,963 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:45:55,284 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:55,284 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:45:55,841 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 03:45:55,841 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [962773714] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:45:55,842 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [968021453] [2022-11-03 03:45:55,865 INFO L159 IcfgInterpreter]: Started Sifa with 37 locations of interest [2022-11-03 03:45:55,865 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:45:55,870 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:45:55,877 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:45:55,877 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:46:00,799 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 294 for LOIs [2022-11-03 03:46:00,856 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 316 for LOIs [2022-11-03 03:46:03,044 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 311 for LOIs [2022-11-03 03:46:05,055 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 27 for LOIs [2022-11-03 03:46:05,058 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 292 for LOIs [2022-11-03 03:46:05,122 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:46:30,917 WARN L234 SmtUtils]: Spent 5.22s on a formula simplification. DAG size of input: 345 DAG size of output: 325 (called from [L 360] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-11-03 03:46:36,348 WARN L234 SmtUtils]: Spent 5.04s on a formula simplification. DAG size of input: 347 DAG size of output: 327 (called from [L 360] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-11-03 03:46:56,638 WARN L234 SmtUtils]: Spent 5.92s on a formula simplification. DAG size of input: 349 DAG size of output: 316 (called from [L 360] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-11-03 03:46:58,732 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '4165#(and (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~5#1|) (<= 0 |#NULL.base|) (<= 0 |old(~pumpRunning~0)|) (<= ~pumpRunning~0 1) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (<= 2 ~waterLevel~0) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~5#1|) (<= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1|) (= ~methaneLevelCritical~0 1) (<= |old(~pumpRunning~0)| 0) (<= 2 |old(~waterLevel~0)|) (<= 0 ~head~0.base) (<= |#NULL.base| 0) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1| 0)) (<= 0 |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1|) (<= 0 |#NULL.offset|) (<= 0 |#StackHeapBarrier|) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 1) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4))' at error location [2022-11-03 03:46:58,732 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:46:58,732 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:46:58,733 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 10, 10] total 24 [2022-11-03 03:46:58,733 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2101018188] [2022-11-03 03:46:58,733 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:46:58,734 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 24 states [2022-11-03 03:46:58,734 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:46:58,734 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 24 interpolants. [2022-11-03 03:46:58,736 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=337, Invalid=2213, Unknown=0, NotChecked=0, Total=2550 [2022-11-03 03:46:58,736 INFO L87 Difference]: Start difference. First operand 374 states and 461 transitions. Second operand has 24 states, 18 states have (on average 3.2777777777777777) internal successors, (59), 18 states have internal predecessors, (59), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) [2022-11-03 03:47:04,425 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:47:04,425 INFO L93 Difference]: Finished difference Result 1506 states and 2057 transitions. [2022-11-03 03:47:04,426 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 72 states. [2022-11-03 03:47:04,426 INFO L78 Accepts]: Start accepts. Automaton has has 24 states, 18 states have (on average 3.2777777777777777) internal successors, (59), 18 states have internal predecessors, (59), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) Word has length 38 [2022-11-03 03:47:04,428 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:47:04,442 INFO L225 Difference]: With dead ends: 1506 [2022-11-03 03:47:04,446 INFO L226 Difference]: Without dead ends: 1132 [2022-11-03 03:47:04,451 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 203 GetRequests, 84 SyntacticMatches, 6 SemanticMatches, 113 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4911 ImplicationChecksByTransitivity, 57.0s TimeCoverageRelationStatistics Valid=1552, Invalid=11558, Unknown=0, NotChecked=0, Total=13110 [2022-11-03 03:47:04,452 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 1194 mSDsluCounter, 720 mSDsCounter, 0 mSdLazyCounter, 2644 mSolverCounterSat, 893 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 2.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1199 SdHoareTripleChecker+Valid, 723 SdHoareTripleChecker+Invalid, 3537 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 893 IncrementalHoareTripleChecker+Valid, 2644 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.4s IncrementalHoareTripleChecker+Time [2022-11-03 03:47:04,452 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1199 Valid, 723 Invalid, 3537 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [893 Valid, 2644 Invalid, 0 Unknown, 0 Unchecked, 2.4s Time] [2022-11-03 03:47:04,455 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1132 states. [2022-11-03 03:47:04,540 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1132 to 779. [2022-11-03 03:47:04,542 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 779 states, 547 states have (on average 1.2413162705667276) internal successors, (679), 586 states have internal predecessors, (679), 114 states have call successors, (114), 106 states have call predecessors, (114), 117 states have return successors, (148), 117 states have call predecessors, (148), 114 states have call successors, (148) [2022-11-03 03:47:04,550 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 779 states to 779 states and 941 transitions. [2022-11-03 03:47:04,551 INFO L78 Accepts]: Start accepts. Automaton has 779 states and 941 transitions. Word has length 38 [2022-11-03 03:47:04,551 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:47:04,552 INFO L495 AbstractCegarLoop]: Abstraction has 779 states and 941 transitions. [2022-11-03 03:47:04,552 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 24 states, 18 states have (on average 3.2777777777777777) internal successors, (59), 18 states have internal predecessors, (59), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) [2022-11-03 03:47:04,552 INFO L276 IsEmpty]: Start isEmpty. Operand 779 states and 941 transitions. [2022-11-03 03:47:04,555 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2022-11-03 03:47:04,555 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:47:04,555 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:47:04,592 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-03 03:47:04,772 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:47:04,772 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:47:04,773 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:47:04,773 INFO L85 PathProgramCache]: Analyzing trace with hash 1149268191, now seen corresponding path program 1 times [2022-11-03 03:47:04,773 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:47:04,773 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2051732118] [2022-11-03 03:47:04,773 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:47:04,773 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:47:04,796 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:47:04,835 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 03:47:04,836 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:47:04,836 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2051732118] [2022-11-03 03:47:04,836 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2051732118] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:47:04,836 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:47:04,836 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:47:04,837 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1243210230] [2022-11-03 03:47:04,837 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:47:04,838 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:47:04,838 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:47:04,839 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:47:04,839 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:47:04,839 INFO L87 Difference]: Start difference. First operand 779 states and 941 transitions. Second operand has 4 states, 3 states have (on average 15.666666666666666) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (9), 3 states have call predecessors, (9), 4 states have call successors, (9) [2022-11-03 03:47:04,984 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:47:04,984 INFO L93 Difference]: Finished difference Result 1574 states and 1898 transitions. [2022-11-03 03:47:04,985 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:47:04,985 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 15.666666666666666) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (9), 3 states have call predecessors, (9), 4 states have call successors, (9) Word has length 70 [2022-11-03 03:47:04,985 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:47:04,989 INFO L225 Difference]: With dead ends: 1574 [2022-11-03 03:47:04,989 INFO L226 Difference]: Without dead ends: 536 [2022-11-03 03:47:04,991 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:47:04,992 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 87 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 78 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 87 SdHoareTripleChecker+Valid, 120 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 78 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:47:04,992 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [87 Valid, 120 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 78 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:47:04,994 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 536 states. [2022-11-03 03:47:05,057 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 536 to 514. [2022-11-03 03:47:05,058 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 514 states, 349 states have (on average 1.166189111747851) internal successors, (407), 374 states have internal predecessors, (407), 79 states have call successors, (79), 74 states have call predecessors, (79), 85 states have return successors, (99), 83 states have call predecessors, (99), 79 states have call successors, (99) [2022-11-03 03:47:05,062 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 514 states to 514 states and 585 transitions. [2022-11-03 03:47:05,062 INFO L78 Accepts]: Start accepts. Automaton has 514 states and 585 transitions. Word has length 70 [2022-11-03 03:47:05,063 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:47:05,063 INFO L495 AbstractCegarLoop]: Abstraction has 514 states and 585 transitions. [2022-11-03 03:47:05,063 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 15.666666666666666) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (9), 3 states have call predecessors, (9), 4 states have call successors, (9) [2022-11-03 03:47:05,063 INFO L276 IsEmpty]: Start isEmpty. Operand 514 states and 585 transitions. [2022-11-03 03:47:05,066 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 68 [2022-11-03 03:47:05,066 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:47:05,066 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:47:05,066 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-03 03:47:05,067 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:47:05,067 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:47:05,067 INFO L85 PathProgramCache]: Analyzing trace with hash 1074357167, now seen corresponding path program 1 times [2022-11-03 03:47:05,067 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:47:05,068 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1652094947] [2022-11-03 03:47:05,068 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:47:05,068 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:47:05,102 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:47:05,691 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 5 proven. 11 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 03:47:05,691 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:47:05,691 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1652094947] [2022-11-03 03:47:05,691 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1652094947] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:47:05,691 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1365284537] [2022-11-03 03:47:05,691 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:47:05,692 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:47:05,692 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:47:05,693 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:47:05,702 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 03:47:05,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:47:05,810 INFO L263 TraceCheckSpWp]: Trace formula consists of 434 conjuncts, 34 conjunts are in the unsatisfiable core [2022-11-03 03:47:05,813 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:47:06,232 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 13 proven. 11 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:47:06,232 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:47:06,843 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 13 proven. 3 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 03:47:06,843 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1365284537] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:47:06,843 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1848022731] [2022-11-03 03:47:06,849 INFO L159 IcfgInterpreter]: Started Sifa with 44 locations of interest [2022-11-03 03:47:06,849 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:47:06,849 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:47:06,850 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:47:06,850 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:47:25,410 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 23 for LOIs [2022-11-03 03:47:25,413 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 43 for LOIs [2022-11-03 03:47:25,683 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 37 for LOIs [2022-11-03 03:47:25,874 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 38 for LOIs [2022-11-03 03:47:25,881 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 39 for LOIs [2022-11-03 03:47:25,889 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 40 for LOIs [2022-11-03 03:47:25,895 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:47:36,327 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '11146#(and (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~5#1|) (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| ~methaneLevelCritical~0) (= ~head~0.offset 0) (<= |timeShift_isPumpRunning_#res#1| 2147483647) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~5#1|) (= 1 ~systemActive~0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1| 0)) (<= 0 (+ |timeShift_isPumpRunning_#res#1| 2147483648)) (<= 0 |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1|) (<= 0 |#StackHeapBarrier|) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:47:36,327 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:47:36,328 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:47:36,328 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 11, 14] total 30 [2022-11-03 03:47:36,328 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [498889240] [2022-11-03 03:47:36,328 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:47:36,329 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 30 states [2022-11-03 03:47:36,329 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:47:36,329 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 30 interpolants. [2022-11-03 03:47:36,331 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=410, Invalid=3130, Unknown=0, NotChecked=0, Total=3540 [2022-11-03 03:47:36,331 INFO L87 Difference]: Start difference. First operand 514 states and 585 transitions. Second operand has 30 states, 27 states have (on average 3.6666666666666665) internal successors, (99), 24 states have internal predecessors, (99), 13 states have call successors, (24), 11 states have call predecessors, (24), 10 states have return successors, (22), 10 states have call predecessors, (22), 13 states have call successors, (22) [2022-11-03 03:47:39,295 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:47:39,296 INFO L93 Difference]: Finished difference Result 1954 states and 2326 transitions. [2022-11-03 03:47:39,296 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 43 states. [2022-11-03 03:47:39,297 INFO L78 Accepts]: Start accepts. Automaton has has 30 states, 27 states have (on average 3.6666666666666665) internal successors, (99), 24 states have internal predecessors, (99), 13 states have call successors, (24), 11 states have call predecessors, (24), 10 states have return successors, (22), 10 states have call predecessors, (22), 13 states have call successors, (22) Word has length 67 [2022-11-03 03:47:39,297 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:47:39,306 INFO L225 Difference]: With dead ends: 1954 [2022-11-03 03:47:39,306 INFO L226 Difference]: Without dead ends: 1579 [2022-11-03 03:47:39,310 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 257 GetRequests, 148 SyntacticMatches, 15 SemanticMatches, 94 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4361 ImplicationChecksByTransitivity, 12.2s TimeCoverageRelationStatistics Valid=1292, Invalid=7828, Unknown=0, NotChecked=0, Total=9120 [2022-11-03 03:47:39,313 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 1172 mSDsluCounter, 548 mSDsCounter, 0 mSdLazyCounter, 1206 mSolverCounterSat, 744 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1177 SdHoareTripleChecker+Valid, 544 SdHoareTripleChecker+Invalid, 1950 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 744 IncrementalHoareTripleChecker+Valid, 1206 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.3s IncrementalHoareTripleChecker+Time [2022-11-03 03:47:39,314 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1177 Valid, 544 Invalid, 1950 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [744 Valid, 1206 Invalid, 0 Unknown, 0 Unchecked, 1.3s Time] [2022-11-03 03:47:39,316 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1579 states. [2022-11-03 03:47:39,484 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1579 to 1434. [2022-11-03 03:47:39,487 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1434 states, 989 states have (on average 1.1688574317492417) internal successors, (1156), 1058 states have internal predecessors, (1156), 223 states have call successors, (223), 181 states have call predecessors, (223), 221 states have return successors, (310), 240 states have call predecessors, (310), 223 states have call successors, (310) [2022-11-03 03:47:39,496 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1434 states to 1434 states and 1689 transitions. [2022-11-03 03:47:39,497 INFO L78 Accepts]: Start accepts. Automaton has 1434 states and 1689 transitions. Word has length 67 [2022-11-03 03:47:39,497 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:47:39,497 INFO L495 AbstractCegarLoop]: Abstraction has 1434 states and 1689 transitions. [2022-11-03 03:47:39,498 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 30 states, 27 states have (on average 3.6666666666666665) internal successors, (99), 24 states have internal predecessors, (99), 13 states have call successors, (24), 11 states have call predecessors, (24), 10 states have return successors, (22), 10 states have call predecessors, (22), 13 states have call successors, (22) [2022-11-03 03:47:39,498 INFO L276 IsEmpty]: Start isEmpty. Operand 1434 states and 1689 transitions. [2022-11-03 03:47:39,502 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 122 [2022-11-03 03:47:39,502 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:47:39,503 INFO L195 NwaCegarLoop]: trace histogram [6, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:47:39,546 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-03 03:47:39,728 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:47:39,729 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:47:39,729 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:47:39,729 INFO L85 PathProgramCache]: Analyzing trace with hash 365085322, now seen corresponding path program 1 times [2022-11-03 03:47:39,729 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:47:39,730 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [242645513] [2022-11-03 03:47:39,730 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:47:39,730 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:47:39,758 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:47:40,940 INFO L134 CoverageAnalysis]: Checked inductivity of 149 backedges. 55 proven. 55 refuted. 0 times theorem prover too weak. 39 trivial. 0 not checked. [2022-11-03 03:47:40,940 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:47:40,941 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [242645513] [2022-11-03 03:47:40,941 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [242645513] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:47:40,941 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2143595183] [2022-11-03 03:47:40,941 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:47:40,941 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:47:40,941 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:47:40,949 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:47:40,968 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 03:47:41,095 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:47:41,099 INFO L263 TraceCheckSpWp]: Trace formula consists of 606 conjuncts, 36 conjunts are in the unsatisfiable core [2022-11-03 03:47:41,104 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:47:41,705 INFO L134 CoverageAnalysis]: Checked inductivity of 149 backedges. 84 proven. 44 refuted. 0 times theorem prover too weak. 21 trivial. 0 not checked. [2022-11-03 03:47:41,705 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:47:42,696 INFO L134 CoverageAnalysis]: Checked inductivity of 149 backedges. 77 proven. 25 refuted. 0 times theorem prover too weak. 47 trivial. 0 not checked. [2022-11-03 03:47:42,696 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2143595183] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:47:42,696 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [574089943] [2022-11-03 03:47:42,699 INFO L159 IcfgInterpreter]: Started Sifa with 47 locations of interest [2022-11-03 03:47:42,699 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:47:42,699 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:47:42,700 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:47:42,700 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:47:54,879 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 40 for LOIs [2022-11-03 03:47:54,887 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 43 for LOIs [2022-11-03 03:47:55,340 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 37 for LOIs [2022-11-03 03:47:55,569 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 38 for LOIs [2022-11-03 03:47:55,578 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 39 for LOIs [2022-11-03 03:47:55,584 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 40 for LOIs [2022-11-03 03:47:55,589 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 46 for LOIs [2022-11-03 03:47:55,594 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:48:03,377 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '17039#(and (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~5#1|) (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| ~methaneLevelCritical~0) (= ~head~0.offset 0) (<= |timeShift_isPumpRunning_#res#1| 2147483647) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~5#1|) (= 1 ~systemActive~0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1| 0)) (<= 0 (+ |timeShift_isPumpRunning_#res#1| 2147483648)) (<= 0 |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1|) (<= 0 |#StackHeapBarrier|) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:48:03,377 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:48:03,378 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:48:03,378 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [19, 13, 13] total 36 [2022-11-03 03:48:03,378 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [858797895] [2022-11-03 03:48:03,378 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:48:03,379 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 36 states [2022-11-03 03:48:03,379 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:48:03,380 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 36 interpolants. [2022-11-03 03:48:03,381 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=479, Invalid=3943, Unknown=0, NotChecked=0, Total=4422 [2022-11-03 03:48:03,381 INFO L87 Difference]: Start difference. First operand 1434 states and 1689 transitions. Second operand has 36 states, 33 states have (on average 5.0606060606060606) internal successors, (167), 34 states have internal predecessors, (167), 23 states have call successors, (39), 9 states have call predecessors, (39), 15 states have return successors, (41), 18 states have call predecessors, (41), 23 states have call successors, (41) [2022-11-03 03:48:04,557 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:48:04,557 INFO L93 Difference]: Finished difference Result 1945 states and 2311 transitions. [2022-11-03 03:48:04,558 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 19 states. [2022-11-03 03:48:04,558 INFO L78 Accepts]: Start accepts. Automaton has has 36 states, 33 states have (on average 5.0606060606060606) internal successors, (167), 34 states have internal predecessors, (167), 23 states have call successors, (39), 9 states have call predecessors, (39), 15 states have return successors, (41), 18 states have call predecessors, (41), 23 states have call successors, (41) Word has length 121 [2022-11-03 03:48:04,559 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:48:04,559 INFO L225 Difference]: With dead ends: 1945 [2022-11-03 03:48:04,560 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 03:48:04,565 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 399 GetRequests, 290 SyntacticMatches, 30 SemanticMatches, 79 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4788 ImplicationChecksByTransitivity, 9.0s TimeCoverageRelationStatistics Valid=811, Invalid=5669, Unknown=0, NotChecked=0, Total=6480 [2022-11-03 03:48:04,566 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 475 mSDsluCounter, 432 mSDsCounter, 0 mSdLazyCounter, 542 mSolverCounterSat, 275 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 478 SdHoareTripleChecker+Valid, 432 SdHoareTripleChecker+Invalid, 817 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 275 IncrementalHoareTripleChecker+Valid, 542 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-03 03:48:04,566 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [478 Valid, 432 Invalid, 817 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [275 Valid, 542 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-03 03:48:04,567 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 03:48:04,567 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 03:48:04,567 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 03:48:04,567 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 03:48:04,568 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 121 [2022-11-03 03:48:04,568 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:48:04,568 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 03:48:04,569 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 36 states, 33 states have (on average 5.0606060606060606) internal successors, (167), 34 states have internal predecessors, (167), 23 states have call successors, (39), 9 states have call predecessors, (39), 15 states have return successors, (41), 18 states have call predecessors, (41), 23 states have call successors, (41) [2022-11-03 03:48:04,569 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 03:48:04,569 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 03:48:04,572 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 03:48:04,613 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 03:48:04,788 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-03 03:48:04,790 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 03:48:12,980 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 383 390) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= 0 ~systemActive~0)) [2022-11-03 03:48:12,980 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 383 390) no Hoare annotation was computed. [2022-11-03 03:48:12,981 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 298 304) no Hoare annotation was computed. [2022-11-03 03:48:12,981 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 298 304) the Hoare annotation is: true [2022-11-03 03:48:12,981 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse2 (not (= 0 ~systemActive~0))) (or .cse1 .cse2 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)))) [2022-11-03 03:48:12,981 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2022-11-03 03:48:12,982 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 906 935) no Hoare annotation was computed. [2022-11-03 03:48:12,982 INFO L899 garLoopResultBuilder]: For program point L927(line 927) no Hoare annotation was computed. [2022-11-03 03:48:12,982 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 906 935) the Hoare annotation is: true [2022-11-03 03:48:12,982 INFO L899 garLoopResultBuilder]: For program point L920(lines 920 924) no Hoare annotation was computed. [2022-11-03 03:48:12,982 INFO L902 garLoopResultBuilder]: At program point L920-1(lines 920 924) the Hoare annotation is: true [2022-11-03 03:48:12,982 INFO L902 garLoopResultBuilder]: At program point L916-2(lines 916 930) the Hoare annotation is: true [2022-11-03 03:48:12,983 INFO L902 garLoopResultBuilder]: At program point L912(line 912) the Hoare annotation is: true [2022-11-03 03:48:12,983 INFO L899 garLoopResultBuilder]: For program point L912-1(line 912) no Hoare annotation was computed. [2022-11-03 03:48:12,983 INFO L902 garLoopResultBuilder]: At program point L931(lines 906 935) the Hoare annotation is: true [2022-11-03 03:48:12,983 INFO L895 garLoopResultBuilder]: At program point L193(line 193) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1) (or .cse1 (not (= |old(~waterLevel~0)| 2))) (or .cse0 (not (= 0 ~systemActive~0))))) [2022-11-03 03:48:12,984 INFO L895 garLoopResultBuilder]: At program point L346(line 346) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1) (or .cse1 (not (= |old(~waterLevel~0)| 2))) (or .cse0 (not (= 0 ~systemActive~0))))) [2022-11-03 03:48:12,984 INFO L895 garLoopResultBuilder]: At program point L342(line 342) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1) (or .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_processEnvironment_~tmp~3#1| 1) (= ~waterLevel~0 1))) (or .cse0 (not (= 0 ~systemActive~0))))) [2022-11-03 03:48:12,985 INFO L895 garLoopResultBuilder]: At program point L169(line 169) the Hoare annotation is: (let ((.cse10 (= 0 ~systemActive~0)) (.cse7 (= ~methaneLevelCritical~0 0))) (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (not (= 1 ~systemActive~0))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse5 (not (= ~methaneLevelCritical~0 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse11 (not (= |old(~waterLevel~0)| 1))) (.cse6 (not .cse7)) (.cse8 (= ~waterLevel~0 1)) (.cse2 (not .cse10))) (and (or .cse0 .cse1 .cse2) (or .cse3 (and .cse4 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse5) (or (and .cse1 .cse6) (and .cse7 (= ~pumpRunning~0 1)))) (and .cse1 (= |timeShift_processEnvironment_~tmp~3#1| 1) .cse8) .cse9) (or .cse0 .cse3 (< |old(~waterLevel~0)| 2) .cse4 .cse10 (not (<= |old(~waterLevel~0)| 2))) (or .cse0 .cse11 .cse3 (and .cse1 .cse8) .cse10) (or .cse3 .cse6 (not (= |old(~pumpRunning~0)| 1)) .cse9 .cse8) (or .cse0 .cse11 .cse5 .cse8 .cse2) (or .cse0 .cse11 .cse6 .cse8 .cse2)))) [2022-11-03 03:48:12,985 INFO L899 garLoopResultBuilder]: For program point L169-1(line 169) no Hoare annotation was computed. [2022-11-03 03:48:12,985 INFO L895 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2) (or .cse3 (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse1 (= ~waterLevel~0 1))) (or .cse0 .cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-03 03:48:12,986 INFO L895 garLoopResultBuilder]: At program point L351-1(lines 332 356) the Hoare annotation is: (let ((.cse4 (= ~methaneLevelCritical~0 0))) (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not .cse4)) (.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse5 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 1))) (or (and .cse2 .cse3) (and .cse4 (= ~pumpRunning~0 1)))) (and .cse2 (= |timeShift_processEnvironment_~tmp~3#1| 1) .cse5) .cse6) (or .cse7 .cse0 (< |old(~waterLevel~0)| 2) .cse1 .cse8 (not (<= |old(~waterLevel~0)| 2))) (or .cse7 (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse2 .cse5) .cse8) (or .cse0 .cse3 (not (= |old(~pumpRunning~0)| 1)) .cse6 .cse5) (or .cse7 (not .cse8))))) [2022-11-03 03:48:12,986 INFO L899 garLoopResultBuilder]: For program point L285-1(lines 285 291) no Hoare annotation was computed. [2022-11-03 03:48:12,986 INFO L899 garLoopResultBuilder]: For program point L278-1(lines 277 296) no Hoare annotation was computed. [2022-11-03 03:48:12,986 INFO L899 garLoopResultBuilder]: For program point L340(lines 340 348) no Hoare annotation was computed. [2022-11-03 03:48:12,987 INFO L895 garLoopResultBuilder]: At program point L336(lines 336 353) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 (= ~waterLevel~0 1))) (or .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (or (and .cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (and (not .cse2) (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))))) (not (= |old(~waterLevel~0)| 2))) (or .cse0 (not (= 0 ~systemActive~0))))) [2022-11-03 03:48:12,987 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 274 297) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse4 (not (= 1 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~waterLevel~0)| 1))) (.cse5 (= ~waterLevel~0 1)) (.cse2 (not (= 0 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse4 (and .cse1 .cse5)) (or .cse0 .cse3 (not (= ~methaneLevelCritical~0 1)) .cse5 .cse2) (or .cse4 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= |old(~waterLevel~0)| 2))) (or .cse0 .cse3 (not (= ~methaneLevelCritical~0 0)) .cse5 .cse2))) [2022-11-03 03:48:12,987 INFO L899 garLoopResultBuilder]: For program point L175(lines 175 181) no Hoare annotation was computed. [2022-11-03 03:48:12,988 INFO L895 garLoopResultBuilder]: At program point L171(lines 171 184) the Hoare annotation is: (let ((.cse10 (= ~methaneLevelCritical~0 0))) (let ((.cse17 (= 0 ~systemActive~0)) (.cse5 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (not .cse10))) (let ((.cse12 (not (= |old(~waterLevel~0)| 2))) (.cse13 (and (or .cse0 .cse10) (or .cse9 (not (= |old(~pumpRunning~0)| 1))))) (.cse15 (< |old(~waterLevel~0)| 2)) (.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse16 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse8 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not .cse5)) (.cse14 (not (= |old(~waterLevel~0)| 1))) (.cse11 (= ~waterLevel~0 1)) (.cse2 (not .cse17))) (and (or .cse0 .cse1 .cse2) (or .cse3 (let ((.cse6 (= ~pumpRunning~0 1))) (and (or (and .cse1 .cse4) (and .cse5 .cse6)) .cse7 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse8) (or (and .cse1 .cse9) (and .cse10 .cse6)))) (and .cse1 (= |timeShift_processEnvironment_~tmp~3#1| 1) .cse11) .cse12) (or .cse5 .cse3 .cse13 .cse9 .cse12) (or .cse0 .cse14 .cse3 .cse8 .cse4) (or .cse0 .cse5 .cse9 .cse2) (or .cse3 .cse15 .cse13 .cse11 .cse16 .cse4) (or .cse0 .cse5 .cse14 .cse3 .cse9) (or .cse0 .cse3 .cse15 .cse7 .cse17 .cse16) (or .cse0 .cse14 .cse3 (and .cse1 .cse11) .cse17) (or .cse0 .cse14 .cse8 .cse11 .cse2) (or .cse0 .cse10 .cse4 .cse2) (or .cse0 .cse14 .cse9 .cse11 .cse2))))) [2022-11-03 03:48:12,988 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 274 297) no Hoare annotation was computed. [2022-11-03 03:48:12,989 INFO L895 garLoopResultBuilder]: At program point L171-1(lines 163 187) the Hoare annotation is: (let ((.cse3 (= ~methaneLevelCritical~0 0)) (.cse7 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0))) (let ((.cse12 (<= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1| 0)) (.cse13 (< 0 (+ |timeShift___utac_acc__Specification1_spec__1_~tmp___0~0#1| 1))) (.cse6 (not .cse7)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not .cse3))) (let ((.cse11 (not (= |old(~waterLevel~0)| 2))) (.cse1 (= ~pumpRunning~0 0)) (.cse17 (and (or .cse0 .cse3) (or .cse4 (not (= |old(~pumpRunning~0)| 1))))) (.cse10 (not (= 1 ~systemActive~0))) (.cse16 (and .cse12 .cse13 .cse6)) (.cse14 (not (= ~methaneLevelCritical~0 1))) (.cse18 (not (= |old(~waterLevel~0)| 1))) (.cse2 (= ~waterLevel~0 1)) (.cse15 (not (= 0 ~systemActive~0)))) (and (let ((.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse9 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse14))) (or (and .cse0 .cse1 (= |timeShift_processEnvironment_~tmp~3#1| 1) .cse2) (let ((.cse5 (= ~pumpRunning~0 1))) (and (or .cse3 (and (<= ~pumpRunning~0 0) (not (= |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#t~ret18#1| 0)))) (or .cse4 .cse5) (or (and .cse1 .cse6) (and .cse7 .cse5)) .cse8 .cse9 (or .cse3 (not (= |isMethaneLevelCritical_#res| 0))))) .cse10 .cse11 (and .cse1 .cse4 .cse12 .cse13 .cse8 .cse9 .cse6))) (or .cse0 .cse1 .cse15) (or .cse0 .cse3 .cse16 .cse15) (or .cse7 .cse10 .cse17 .cse4 .cse11) (or .cse0 .cse7 .cse4 .cse15) (or .cse0 .cse18 .cse10 (and .cse1 .cse2)) (or .cse0 .cse7 .cse18 .cse10 .cse4) (or .cse10 (< |old(~waterLevel~0)| 2) .cse17 .cse16 .cse2 (not (<= |old(~waterLevel~0)| 2))) (or .cse0 .cse18 .cse10 .cse16 .cse14) (or .cse0 .cse18 .cse14 .cse2 .cse15) (or .cse0 .cse18 .cse4 .cse2 .cse15))))) [2022-11-03 03:48:12,989 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 193) no Hoare annotation was computed. [2022-11-03 03:48:12,989 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 96 104) the Hoare annotation is: true [2022-11-03 03:48:12,990 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 96 104) no Hoare annotation was computed. [2022-11-03 03:48:12,990 INFO L899 garLoopResultBuilder]: For program point L221(lines 221 227) no Hoare annotation was computed. [2022-11-03 03:48:12,990 INFO L899 garLoopResultBuilder]: For program point L221-1(lines 221 227) no Hoare annotation was computed. [2022-11-03 03:48:12,990 INFO L895 garLoopResultBuilder]: At program point L259(lines 210 260) the Hoare annotation is: false [2022-11-03 03:48:12,990 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 03:48:12,991 INFO L899 garLoopResultBuilder]: For program point L247(lines 247 253) no Hoare annotation was computed. [2022-11-03 03:48:12,991 INFO L895 garLoopResultBuilder]: At program point L247-2(lines 241 254) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0))) (let ((.cse1 (= 1 ~systemActive~0)) (.cse3 (not .cse4)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 .cse2 .cse4)))) [2022-11-03 03:48:12,991 INFO L895 garLoopResultBuilder]: At program point L491(line 491) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (or (not (= ~pumpRunning~0 0)) (= ~methaneLevelCritical~0 0) (not (= |isMethaneLevelCritical_#res| 0))) (not (= 0 ~systemActive~0))) [2022-11-03 03:48:12,991 INFO L899 garLoopResultBuilder]: For program point L231(lines 231 237) no Hoare annotation was computed. [2022-11-03 03:48:12,991 INFO L899 garLoopResultBuilder]: For program point L231-1(lines 231 237) no Hoare annotation was computed. [2022-11-03 03:48:12,992 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 03:48:12,992 INFO L895 garLoopResultBuilder]: At program point L256(lines 211 258) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 (let ((.cse3 (= ~methaneLevelCritical~0 0))) (or (and .cse2 (not .cse3)) (and .cse3 (= ~pumpRunning~0 1))))) (and .cse2 .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (= 0 ~systemActive~0)))) [2022-11-03 03:48:12,992 INFO L895 garLoopResultBuilder]: At program point L223(line 223) the Hoare annotation is: (let ((.cse5 (= 0 ~systemActive~0))) (let ((.cse1 (= 1 ~systemActive~0)) (.cse3 (not .cse5)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) (let ((.cse4 (= ~methaneLevelCritical~0 0))) (or (and .cse0 (not .cse4)) (and .cse4 (= ~pumpRunning~0 1)))) .cse3) (and .cse0 .cse2 .cse5)))) [2022-11-03 03:48:12,993 INFO L895 garLoopResultBuilder]: At program point L987(lines 987 994) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_main_~tmp~10#1| ~systemActive~0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-03 03:48:12,993 INFO L902 garLoopResultBuilder]: At program point L987-2(lines 987 994) the Hoare annotation is: true [2022-11-03 03:48:12,993 INFO L899 garLoopResultBuilder]: For program point L212(lines 211 258) no Hoare annotation was computed. [2022-11-03 03:48:12,993 INFO L899 garLoopResultBuilder]: For program point L241(lines 241 254) no Hoare annotation was computed. [2022-11-03 03:48:12,993 INFO L895 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0))) (let ((.cse1 (= 1 ~systemActive~0)) (.cse3 (not .cse4)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 .cse2 .cse4)))) [2022-11-03 03:48:12,994 INFO L899 garLoopResultBuilder]: For program point L489(lines 489 495) no Hoare annotation was computed. [2022-11-03 03:48:12,994 INFO L895 garLoopResultBuilder]: At program point L489-1(lines 489 495) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-03 03:48:12,994 INFO L902 garLoopResultBuilder]: At program point L262(lines 201 266) the Hoare annotation is: true [2022-11-03 03:48:12,994 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 306 330) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)))) [2022-11-03 03:48:12,995 INFO L895 garLoopResultBuilder]: At program point L320(line 320) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0))))) [2022-11-03 03:48:12,995 INFO L899 garLoopResultBuilder]: For program point L314(lines 314 322) no Hoare annotation was computed. [2022-11-03 03:48:12,995 INFO L895 garLoopResultBuilder]: At program point L310(lines 310 327) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)))) [2022-11-03 03:48:12,995 INFO L895 garLoopResultBuilder]: At program point L325(line 325) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)))) [2022-11-03 03:48:12,996 INFO L899 garLoopResultBuilder]: For program point L325-1(lines 306 330) no Hoare annotation was computed. [2022-11-03 03:48:12,996 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 306 330) no Hoare annotation was computed. [2022-11-03 03:48:12,996 INFO L895 garLoopResultBuilder]: At program point L396(line 396) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 1)) (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2)))) [2022-11-03 03:48:12,996 INFO L895 garLoopResultBuilder]: At program point L396-1(line 396) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1) (or .cse0 .cse1 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) (and (= |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#t~ret18#1| ~methaneLevelCritical~0) (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 1))))) [2022-11-03 03:48:12,997 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2022-11-03 03:48:12,997 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (= ~waterLevel~0 1)) (or (let ((.cse2 (= ~methaneLevelCritical~0 0))) (and (or .cse0 .cse2) (or (not .cse2) (not (= ~pumpRunning~0 1))))) .cse1 (< |old(~waterLevel~0)| 2) (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= |old(~waterLevel~0)| 2))))) [2022-11-03 03:48:13,001 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:48:13,003 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 03:48:13,036 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 03:48:13 BoogieIcfgContainer [2022-11-03 03:48:13,036 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 03:48:13,037 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 03:48:13,037 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 03:48:13,037 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 03:48:13,038 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:51" (3/4) ... [2022-11-03 03:48:13,041 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 03:48:13,048 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-03 03:48:13,048 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 03:48:13,048 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 03:48:13,048 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 03:48:13,049 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 03:48:13,049 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-03 03:48:13,049 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:48:13,049 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 03:48:13,058 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 77 nodes and edges [2022-11-03 03:48:13,058 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 28 nodes and edges [2022-11-03 03:48:13,059 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-03 03:48:13,060 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 03:48:13,060 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 03:48:13,061 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:48:13,061 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:48:13,090 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) [2022-11-03 03:48:13,091 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && ((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)))) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:48:13,091 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || ((pumpRunning == 0 && tmp == 1) && waterLevel == 1)) || !(\old(waterLevel) == 2)) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:48:13,091 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || waterLevel < 2) [2022-11-03 03:48:13,092 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((!(1 == systemActive) || (((((pumpRunning == 0 && !(tmp == 0)) || (tmp == 0 && pumpRunning == 1)) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || ((pumpRunning == 0 && tmp == 1) && waterLevel == 1)) || !(\old(waterLevel) == 2))) && ((((tmp == 0 || !(1 == systemActive)) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(tmp == 0))) && (((!(\old(pumpRunning) == 0) || tmp == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((((!(1 == systemActive) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || waterLevel == 1) || !(\old(waterLevel) <= 2)) || !(tmp == 0))) && ((((!(\old(pumpRunning) == 0) || tmp == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || !(tmp == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) [2022-11-03 03:48:13,092 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && tmp == 1) && waterLevel == 1) || ((((((methaneLevelCritical == 0 || (pumpRunning <= 0 && !(aux-isMethaneLevelCritical()-aux == 0))) && (!(methaneLevelCritical == 0) || pumpRunning == 1)) && ((pumpRunning == 0 && !(tmp == 0)) || (tmp == 0 && pumpRunning == 1))) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && (methaneLevelCritical == 0 || !(\result == 0)))) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || ((((((pumpRunning == 0 && !(methaneLevelCritical == 0)) && tmp___0 <= 0) && 0 < tmp___0 + 1) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && !(tmp == 0))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || !(0 == systemActive))) && ((((tmp == 0 || !(1 == systemActive)) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || tmp == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && ((((!(\old(pumpRunning) == 0) || tmp == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((((!(1 == systemActive) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) [2022-11-03 03:48:13,092 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || waterLevel < 2) || ((aux-isMethaneLevelCritical()-aux == methaneLevelCritical && pumpRunning == 0) && tmp == 1)) [2022-11-03 03:48:13,093 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) && (!(1 == systemActive) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:48:13,122 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 03:48:13,122 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 03:48:13,123 INFO L158 Benchmark]: Toolchain (without parser) took 142804.55ms. Allocated memory was 107.0MB in the beginning and 826.3MB in the end (delta: 719.3MB). Free memory was 67.3MB in the beginning and 509.9MB in the end (delta: -442.6MB). Peak memory consumption was 276.7MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,123 INFO L158 Benchmark]: CDTParser took 0.34ms. Allocated memory is still 107.0MB. Free memory is still 84.7MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:48:13,124 INFO L158 Benchmark]: CACSL2BoogieTranslator took 595.86ms. Allocated memory is still 107.0MB. Free memory was 67.2MB in the beginning and 72.0MB in the end (delta: -4.8MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,124 INFO L158 Benchmark]: Boogie Procedure Inliner took 58.19ms. Allocated memory is still 107.0MB. Free memory was 72.0MB in the beginning and 69.4MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,124 INFO L158 Benchmark]: Boogie Preprocessor took 39.49ms. Allocated memory is still 107.0MB. Free memory was 69.4MB in the beginning and 67.8MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,125 INFO L158 Benchmark]: RCFGBuilder took 720.41ms. Allocated memory is still 107.0MB. Free memory was 67.4MB in the beginning and 81.0MB in the end (delta: -13.6MB). Peak memory consumption was 35.9MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,125 INFO L158 Benchmark]: TraceAbstraction took 141293.60ms. Allocated memory was 107.0MB in the beginning and 826.3MB in the end (delta: 719.3MB). Free memory was 80.3MB in the beginning and 515.2MB in the end (delta: -434.9MB). Peak memory consumption was 509.5MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,126 INFO L158 Benchmark]: Witness Printer took 85.51ms. Allocated memory is still 826.3MB. Free memory was 515.2MB in the beginning and 509.9MB in the end (delta: 5.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-03 03:48:13,127 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.34ms. Allocated memory is still 107.0MB. Free memory is still 84.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 595.86ms. Allocated memory is still 107.0MB. Free memory was 67.2MB in the beginning and 72.0MB in the end (delta: -4.8MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 58.19ms. Allocated memory is still 107.0MB. Free memory was 72.0MB in the beginning and 69.4MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 39.49ms. Allocated memory is still 107.0MB. Free memory was 69.4MB in the beginning and 67.8MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 720.41ms. Allocated memory is still 107.0MB. Free memory was 67.4MB in the beginning and 81.0MB in the end (delta: -13.6MB). Peak memory consumption was 35.9MB. Max. memory is 16.1GB. * TraceAbstraction took 141293.60ms. Allocated memory was 107.0MB in the beginning and 826.3MB in the end (delta: 719.3MB). Free memory was 80.3MB in the beginning and 515.2MB in the end (delta: -434.9MB). Peak memory consumption was 509.5MB. Max. memory is 16.1GB. * Witness Printer took 85.51ms. Allocated memory is still 826.3MB. Free memory was 515.2MB in the beginning and 509.9MB in the end (delta: 5.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 193]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 65 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 141.2s, OverallIterations: 10, TraceHistogramMax: 6, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 11.1s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 8.2s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3261 SdHoareTripleChecker+Valid, 4.8s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3240 mSDsluCounter, 2733 SdHoareTripleChecker+Invalid, 3.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2400 mSDsCounter, 1968 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4833 IncrementalHoareTripleChecker+Invalid, 6801 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1968 mSolverCounterUnsat, 702 mSDtfsCounter, 4833 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 896 GetRequests, 538 SyntacticMatches, 51 SemanticMatches, 307 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14065 ImplicationChecksByTransitivity, 78.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1434occurred in iteration=9, InterpolantAutomatonStates: 166, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 10 MinimizatonAttempts, 613 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 37 LocationsWithAnnotation, 2229 PreInvPairs, 2517 NumberOfFragments, 1848 HoareAnnotationTreeSize, 2229 FomulaSimplifications, 7329 FormulaSimplificationTreeSizeReduction, 0.9s HoareSimplificationTime, 37 FomulaSimplificationsInter, 44869 FormulaSimplificationTreeSizeReductionInter, 7.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 6.6s InterpolantComputationTime, 659 NumberOfCodeBlocks, 659 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 869 ConstructedInterpolants, 0 QuantifiedInterpolants, 3600 SizeOfPredicates, 38 NumberOfNonLiveVariables, 1391 ConjunctsInSsa, 101 ConjunctsInUnsatCore, 16 InterpolantComputations, 7 PerfectInterpolantSequences, 406/559 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 332]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || ((pumpRunning == 0 && tmp == 1) && waterLevel == 1)) || !(\old(waterLevel) == 2)) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 210]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 211]: Loop Invariant Derived loop invariant: ((((2 == waterLevel && 1 == systemActive) && splverifierCounter == 0) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1))) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1)) || ((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 489]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 171]: Loop Invariant Derived loop invariant: ((((((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((!(1 == systemActive) || (((((pumpRunning == 0 && !(tmp == 0)) || (tmp == 0 && pumpRunning == 1)) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || ((pumpRunning == 0 && tmp == 1) && waterLevel == 1)) || !(\old(waterLevel) == 2))) && ((((tmp == 0 || !(1 == systemActive)) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(tmp == 0))) && (((!(\old(pumpRunning) == 0) || tmp == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((((!(1 == systemActive) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || waterLevel == 1) || !(\old(waterLevel) <= 2)) || !(tmp == 0))) && ((((!(\old(pumpRunning) == 0) || tmp == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || !(tmp == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) - InvariantResult [Line: 163]: Loop Invariant Derived loop invariant: ((((((((((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && tmp == 1) && waterLevel == 1) || ((((((methaneLevelCritical == 0 || (pumpRunning <= 0 && !(aux-isMethaneLevelCritical()-aux == 0))) && (!(methaneLevelCritical == 0) || pumpRunning == 1)) && ((pumpRunning == 0 && !(tmp == 0)) || (tmp == 0 && pumpRunning == 1))) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && (methaneLevelCritical == 0 || !(\result == 0)))) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || ((((((pumpRunning == 0 && !(methaneLevelCritical == 0)) && tmp___0 <= 0) && 0 < tmp___0 + 1) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && !(tmp == 0))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || !(0 == systemActive))) && ((((tmp == 0 || !(1 == systemActive)) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || tmp == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && ((((!(\old(pumpRunning) == 0) || tmp == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((((!(1 == systemActive) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || waterLevel == 1) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp___0 <= 0 && 0 < tmp___0 + 1) && !(tmp == 0))) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) - InvariantResult [Line: 193]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) && (!(1 == systemActive) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 274]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || waterLevel == 1) || !(0 == systemActive)) - InvariantResult [Line: 396]: Loop Invariant Derived loop invariant: ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || waterLevel < 2) || ((aux-isMethaneLevelCritical()-aux == methaneLevelCritical && pumpRunning == 0) && tmp == 1)) - InvariantResult [Line: 916]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 201]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 987]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && tmp == systemActive) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 987]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 336]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && ((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)))) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 310]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || waterLevel < 2) RESULT: Ultimate proved your program to be correct! [2022-11-03 03:48:13,193 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_36fa4ff8-d6e8-4805-9f6c-9396599dd485/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE