./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 1b223e2286b1d2d2d4710f5bd529ee4610cfb9619424734c12c9aa00d3c99444 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 03:27:41,496 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 03:27:41,499 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 03:27:41,553 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 03:27:41,554 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 03:27:41,559 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 03:27:41,561 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 03:27:41,565 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 03:27:41,569 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 03:27:41,579 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 03:27:41,580 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 03:27:41,581 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 03:27:41,582 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 03:27:41,585 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 03:27:41,587 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 03:27:41,590 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 03:27:41,592 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 03:27:41,593 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 03:27:41,595 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 03:27:41,600 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 03:27:41,605 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 03:27:41,608 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 03:27:41,611 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 03:27:41,613 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 03:27:41,621 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 03:27:41,626 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 03:27:41,627 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 03:27:41,628 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 03:27:41,629 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 03:27:41,631 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 03:27:41,631 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 03:27:41,632 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 03:27:41,634 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 03:27:41,636 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 03:27:41,638 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 03:27:41,638 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 03:27:41,639 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 03:27:41,639 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 03:27:41,640 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 03:27:41,641 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 03:27:41,641 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 03:27:41,643 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 03:27:41,691 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 03:27:41,691 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 03:27:41,692 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 03:27:41,693 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 03:27:41,694 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 03:27:41,694 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 03:27:41,694 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 03:27:41,695 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 03:27:41,695 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 03:27:41,695 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 03:27:41,696 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 03:27:41,697 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 03:27:41,697 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 03:27:41,697 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 03:27:41,697 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 03:27:41,698 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 03:27:41,698 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 03:27:41,698 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 03:27:41,699 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 03:27:41,699 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 03:27:41,700 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 03:27:41,700 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 03:27:41,700 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 03:27:41,702 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 03:27:41,702 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 03:27:41,702 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 03:27:41,703 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 03:27:41,703 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 03:27:41,703 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 03:27:41,703 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 03:27:41,703 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 03:27:41,704 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 03:27:41,704 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:27:41,704 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 03:27:41,704 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 03:27:41,704 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 03:27:41,705 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 1b223e2286b1d2d2d4710f5bd529ee4610cfb9619424734c12c9aa00d3c99444 [2022-11-03 03:27:42,086 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 03:27:42,126 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 03:27:42,129 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 03:27:42,131 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 03:27:42,132 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 03:27:42,134 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c [2022-11-03 03:27:42,239 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/data/37c88ddf9/6b1be88c5a834d69a9df631a98809c98/FLAG0f73832f8 [2022-11-03 03:27:42,885 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 03:27:42,886 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c [2022-11-03 03:27:42,899 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/data/37c88ddf9/6b1be88c5a834d69a9df631a98809c98/FLAG0f73832f8 [2022-11-03 03:27:43,199 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/data/37c88ddf9/6b1be88c5a834d69a9df631a98809c98 [2022-11-03 03:27:43,202 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 03:27:43,204 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 03:27:43,206 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 03:27:43,206 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 03:27:43,211 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 03:27:43,212 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:43,213 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@440c86bb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43, skipping insertion in model container [2022-11-03 03:27:43,214 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:43,223 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 03:27:43,276 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 03:27:43,781 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c[17002,17015] [2022-11-03 03:27:43,794 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:27:43,805 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 03:27:43,875 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/sv-benchmarks/c/product-lines/minepump_spec2_product40.cil.c[17002,17015] [2022-11-03 03:27:43,880 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:27:43,898 INFO L208 MainTranslator]: Completed translation [2022-11-03 03:27:43,899 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43 WrapperNode [2022-11-03 03:27:43,899 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 03:27:43,900 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 03:27:43,900 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 03:27:43,901 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 03:27:43,914 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:43,944 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:43,997 INFO L138 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 253 [2022-11-03 03:27:43,999 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 03:27:44,000 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 03:27:44,001 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 03:27:44,001 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 03:27:44,013 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,013 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,033 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,034 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,039 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,059 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,060 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,062 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,064 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 03:27:44,065 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 03:27:44,066 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 03:27:44,066 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 03:27:44,067 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (1/1) ... [2022-11-03 03:27:44,075 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:27:44,090 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:27:44,104 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 03:27:44,138 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 03:27:44,158 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 03:27:44,158 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 03:27:44,158 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 03:27:44,158 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 03:27:44,159 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 03:27:44,159 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 03:27:44,159 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 03:27:44,159 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-03 03:27:44,159 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-03 03:27:44,160 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:27:44,160 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:27:44,160 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 03:27:44,160 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 03:27:44,160 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-03 03:27:44,161 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-03 03:27:44,161 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 03:27:44,161 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 03:27:44,161 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 03:27:44,162 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 03:27:44,162 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 03:27:44,272 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 03:27:44,274 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 03:27:44,764 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 03:27:44,934 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 03:27:44,939 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 03:27:44,944 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:27:44 BoogieIcfgContainer [2022-11-03 03:27:44,944 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 03:27:44,947 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 03:27:44,947 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 03:27:44,952 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 03:27:44,952 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 03:27:43" (1/3) ... [2022-11-03 03:27:44,953 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1d917ffe and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:27:44, skipping insertion in model container [2022-11-03 03:27:44,953 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:27:43" (2/3) ... [2022-11-03 03:27:44,954 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1d917ffe and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:27:44, skipping insertion in model container [2022-11-03 03:27:44,954 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:27:44" (3/3) ... [2022-11-03 03:27:44,956 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product40.cil.c [2022-11-03 03:27:44,980 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 03:27:44,980 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 03:27:45,042 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 03:27:45,051 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@6c1cf61d, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 03:27:45,051 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 03:27:45,057 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-03 03:27:45,068 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 18 [2022-11-03 03:27:45,068 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:45,069 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:45,070 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:45,076 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:45,077 INFO L85 PathProgramCache]: Analyzing trace with hash 1865798431, now seen corresponding path program 1 times [2022-11-03 03:27:45,086 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:45,086 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1304908832] [2022-11-03 03:27:45,087 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:45,087 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:45,227 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:45,324 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:45,324 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:45,325 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1304908832] [2022-11-03 03:27:45,326 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1304908832] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:45,326 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:45,327 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 03:27:45,328 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1426471831] [2022-11-03 03:27:45,329 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:45,334 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 03:27:45,335 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:45,367 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 03:27:45,368 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:27:45,371 INFO L87 Difference]: Start difference. First operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:45,492 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:45,494 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2022-11-03 03:27:45,496 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 03:27:45,498 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 17 [2022-11-03 03:27:45,498 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:45,509 INFO L225 Difference]: With dead ends: 130 [2022-11-03 03:27:45,510 INFO L226 Difference]: Without dead ends: 61 [2022-11-03 03:27:45,515 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:27:45,519 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 68 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:45,521 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 68 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:45,542 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-03 03:27:45,571 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-03 03:27:45,573 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 39 states have (on average 1.358974358974359) internal successors, (53), 47 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-03 03:27:45,576 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 80 transitions. [2022-11-03 03:27:45,578 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 80 transitions. Word has length 17 [2022-11-03 03:27:45,579 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:45,579 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 80 transitions. [2022-11-03 03:27:45,579 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:45,580 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 80 transitions. [2022-11-03 03:27:45,582 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 19 [2022-11-03 03:27:45,582 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:45,583 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:45,583 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 03:27:45,583 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:45,584 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:45,585 INFO L85 PathProgramCache]: Analyzing trace with hash -378815255, now seen corresponding path program 1 times [2022-11-03 03:27:45,585 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:45,585 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [904798221] [2022-11-03 03:27:45,585 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:45,586 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:45,616 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:45,795 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:45,796 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:45,796 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [904798221] [2022-11-03 03:27:45,796 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [904798221] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:45,797 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:45,797 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:27:45,797 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1525731962] [2022-11-03 03:27:45,798 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:45,799 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:27:45,799 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:45,800 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:27:45,801 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:45,801 INFO L87 Difference]: Start difference. First operand 61 states and 80 transitions. Second operand has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:45,873 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:45,873 INFO L93 Difference]: Finished difference Result 94 states and 122 transitions. [2022-11-03 03:27:45,874 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:27:45,874 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 18 [2022-11-03 03:27:45,874 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:45,876 INFO L225 Difference]: With dead ends: 94 [2022-11-03 03:27:45,876 INFO L226 Difference]: Without dead ends: 53 [2022-11-03 03:27:45,877 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:45,878 INFO L413 NwaCegarLoop]: 54 mSDtfsCounter, 14 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 26 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 92 SdHoareTripleChecker+Invalid, 26 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 26 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:45,879 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 92 Invalid, 26 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 26 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:27:45,880 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-03 03:27:45,888 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-03 03:27:45,888 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3823529411764706) internal successors, (47), 42 states have internal predecessors, (47), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-03 03:27:45,890 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 69 transitions. [2022-11-03 03:27:45,890 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 69 transitions. Word has length 18 [2022-11-03 03:27:45,891 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:45,891 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 69 transitions. [2022-11-03 03:27:45,891 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:45,892 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 69 transitions. [2022-11-03 03:27:45,893 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 03:27:45,893 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:45,893 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:45,894 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 03:27:45,894 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:45,895 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:45,895 INFO L85 PathProgramCache]: Analyzing trace with hash -245993615, now seen corresponding path program 1 times [2022-11-03 03:27:45,895 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:45,896 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1017614929] [2022-11-03 03:27:45,896 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:45,896 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:45,920 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:46,006 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:46,007 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:46,007 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1017614929] [2022-11-03 03:27:46,007 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1017614929] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:46,008 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:46,008 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:27:46,008 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1412087541] [2022-11-03 03:27:46,008 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:46,009 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:27:46,009 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:46,010 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:27:46,010 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:46,010 INFO L87 Difference]: Start difference. First operand 53 states and 69 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:46,111 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:46,112 INFO L93 Difference]: Finished difference Result 155 states and 204 transitions. [2022-11-03 03:27:46,112 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:27:46,113 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 21 [2022-11-03 03:27:46,113 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:46,115 INFO L225 Difference]: With dead ends: 155 [2022-11-03 03:27:46,115 INFO L226 Difference]: Without dead ends: 104 [2022-11-03 03:27:46,116 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:46,117 INFO L413 NwaCegarLoop]: 73 mSDtfsCounter, 63 mSDsluCounter, 63 mSDsCounter, 0 mSdLazyCounter, 32 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 63 SdHoareTripleChecker+Valid, 125 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 32 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:46,118 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [63 Valid, 125 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 32 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:46,120 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 104 states. [2022-11-03 03:27:46,142 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 104 to 101. [2022-11-03 03:27:46,143 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 101 states, 64 states have (on average 1.390625) internal successors, (89), 79 states have internal predecessors, (89), 22 states have call successors, (22), 14 states have call predecessors, (22), 14 states have return successors, (22), 15 states have call predecessors, (22), 22 states have call successors, (22) [2022-11-03 03:27:46,145 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 101 states to 101 states and 133 transitions. [2022-11-03 03:27:46,146 INFO L78 Accepts]: Start accepts. Automaton has 101 states and 133 transitions. Word has length 21 [2022-11-03 03:27:46,146 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:46,147 INFO L495 AbstractCegarLoop]: Abstraction has 101 states and 133 transitions. [2022-11-03 03:27:46,147 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:46,147 INFO L276 IsEmpty]: Start isEmpty. Operand 101 states and 133 transitions. [2022-11-03 03:27:46,149 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-03 03:27:46,149 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:46,149 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:46,149 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 03:27:46,150 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:46,150 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:46,151 INFO L85 PathProgramCache]: Analyzing trace with hash 1260550476, now seen corresponding path program 1 times [2022-11-03 03:27:46,151 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:46,151 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1737498962] [2022-11-03 03:27:46,151 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:46,152 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:46,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:46,296 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:46,297 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:46,297 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1737498962] [2022-11-03 03:27:46,298 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1737498962] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:46,298 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:46,298 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:27:46,298 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [906057303] [2022-11-03 03:27:46,299 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:46,299 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:27:46,299 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:46,300 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:27:46,300 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:27:46,301 INFO L87 Difference]: Start difference. First operand 101 states and 133 transitions. Second operand has 6 states, 5 states have (on average 4.2) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:46,510 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:46,510 INFO L93 Difference]: Finished difference Result 295 states and 392 transitions. [2022-11-03 03:27:46,511 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 03:27:46,511 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.2) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2022-11-03 03:27:46,512 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:46,515 INFO L225 Difference]: With dead ends: 295 [2022-11-03 03:27:46,515 INFO L226 Difference]: Without dead ends: 196 [2022-11-03 03:27:46,517 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 03:27:46,518 INFO L413 NwaCegarLoop]: 63 mSDtfsCounter, 44 mSDsluCounter, 263 mSDsCounter, 0 mSdLazyCounter, 107 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 47 SdHoareTripleChecker+Valid, 278 SdHoareTripleChecker+Invalid, 109 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 107 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:46,519 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [47 Valid, 278 Invalid, 109 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 107 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:46,520 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 196 states. [2022-11-03 03:27:46,553 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 196 to 188. [2022-11-03 03:27:46,554 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 188 states, 119 states have (on average 1.3697478991596639) internal successors, (163), 146 states have internal predecessors, (163), 42 states have call successors, (42), 26 states have call predecessors, (42), 26 states have return successors, (42), 28 states have call predecessors, (42), 42 states have call successors, (42) [2022-11-03 03:27:46,557 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 188 states to 188 states and 247 transitions. [2022-11-03 03:27:46,558 INFO L78 Accepts]: Start accepts. Automaton has 188 states and 247 transitions. Word has length 24 [2022-11-03 03:27:46,558 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:46,558 INFO L495 AbstractCegarLoop]: Abstraction has 188 states and 247 transitions. [2022-11-03 03:27:46,559 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.2) internal successors, (21), 4 states have internal predecessors, (21), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-03 03:27:46,559 INFO L276 IsEmpty]: Start isEmpty. Operand 188 states and 247 transitions. [2022-11-03 03:27:46,561 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 28 [2022-11-03 03:27:46,562 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:46,562 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:46,562 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 03:27:46,563 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:46,563 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:46,563 INFO L85 PathProgramCache]: Analyzing trace with hash 653436656, now seen corresponding path program 1 times [2022-11-03 03:27:46,564 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:46,564 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [115792158] [2022-11-03 03:27:46,564 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:46,565 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:46,586 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:46,691 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:46,692 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:46,692 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [115792158] [2022-11-03 03:27:46,693 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [115792158] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:46,693 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:46,693 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:27:46,694 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [970710905] [2022-11-03 03:27:46,698 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:46,698 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:27:46,700 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:46,701 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:27:46,701 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:46,702 INFO L87 Difference]: Start difference. First operand 188 states and 247 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:27:46,814 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:46,814 INFO L93 Difference]: Finished difference Result 287 states and 382 transitions. [2022-11-03 03:27:46,815 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:27:46,815 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 27 [2022-11-03 03:27:46,816 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:46,819 INFO L225 Difference]: With dead ends: 287 [2022-11-03 03:27:46,819 INFO L226 Difference]: Without dead ends: 285 [2022-11-03 03:27:46,820 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:27:46,822 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 44 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 5 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 44 SdHoareTripleChecker+Valid, 115 SdHoareTripleChecker+Invalid, 36 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 5 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:46,823 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [44 Valid, 115 Invalid, 36 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [5 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:46,824 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 285 states. [2022-11-03 03:27:46,865 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 285 to 285. [2022-11-03 03:27:46,866 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 180 states have (on average 1.3722222222222222) internal successors, (247), 221 states have internal predecessors, (247), 64 states have call successors, (64), 40 states have call predecessors, (64), 40 states have return successors, (68), 43 states have call predecessors, (68), 64 states have call successors, (68) [2022-11-03 03:27:46,870 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 379 transitions. [2022-11-03 03:27:46,871 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 379 transitions. Word has length 27 [2022-11-03 03:27:46,871 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:46,871 INFO L495 AbstractCegarLoop]: Abstraction has 285 states and 379 transitions. [2022-11-03 03:27:46,872 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:27:46,872 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 379 transitions. [2022-11-03 03:27:46,875 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2022-11-03 03:27:46,875 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:46,875 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:46,876 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 03:27:46,876 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:46,877 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:46,877 INFO L85 PathProgramCache]: Analyzing trace with hash 434397465, now seen corresponding path program 1 times [2022-11-03 03:27:46,877 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:46,877 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1671841260] [2022-11-03 03:27:46,878 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:46,878 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:46,907 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:47,121 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 17 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:27:47,122 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:47,122 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1671841260] [2022-11-03 03:27:47,122 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1671841260] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:47,122 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:47,123 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:27:47,123 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [442755504] [2022-11-03 03:27:47,123 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:47,124 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:27:47,124 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:47,125 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:27:47,125 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:27:47,125 INFO L87 Difference]: Start difference. First operand 285 states and 379 transitions. Second operand has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-03 03:27:47,573 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:47,573 INFO L93 Difference]: Finished difference Result 934 states and 1260 transitions. [2022-11-03 03:27:47,574 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-03 03:27:47,575 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 48 [2022-11-03 03:27:47,575 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:47,586 INFO L225 Difference]: With dead ends: 934 [2022-11-03 03:27:47,587 INFO L226 Difference]: Without dead ends: 651 [2022-11-03 03:27:47,595 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=36, Invalid=74, Unknown=0, NotChecked=0, Total=110 [2022-11-03 03:27:47,602 INFO L413 NwaCegarLoop]: 72 mSDtfsCounter, 129 mSDsluCounter, 127 mSDsCounter, 0 mSdLazyCounter, 157 mSolverCounterSat, 64 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 130 SdHoareTripleChecker+Valid, 175 SdHoareTripleChecker+Invalid, 221 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 64 IncrementalHoareTripleChecker+Valid, 157 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:47,604 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [130 Valid, 175 Invalid, 221 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [64 Valid, 157 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 03:27:47,608 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 651 states. [2022-11-03 03:27:47,727 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 651 to 604. [2022-11-03 03:27:47,730 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 604 states, 406 states have (on average 1.2635467980295567) internal successors, (513), 445 states have internal predecessors, (513), 98 states have call successors, (98), 83 states have call predecessors, (98), 99 states have return successors, (144), 99 states have call predecessors, (144), 98 states have call successors, (144) [2022-11-03 03:27:47,738 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 604 states to 604 states and 755 transitions. [2022-11-03 03:27:47,739 INFO L78 Accepts]: Start accepts. Automaton has 604 states and 755 transitions. Word has length 48 [2022-11-03 03:27:47,739 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:47,739 INFO L495 AbstractCegarLoop]: Abstraction has 604 states and 755 transitions. [2022-11-03 03:27:47,740 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.333333333333333) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-03 03:27:47,740 INFO L276 IsEmpty]: Start isEmpty. Operand 604 states and 755 transitions. [2022-11-03 03:27:47,751 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2022-11-03 03:27:47,751 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:47,752 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:47,752 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 03:27:47,752 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:47,753 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:47,753 INFO L85 PathProgramCache]: Analyzing trace with hash -2099161350, now seen corresponding path program 1 times [2022-11-03 03:27:47,753 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:47,755 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1868923003] [2022-11-03 03:27:47,755 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:47,755 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:47,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:47,902 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 17 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:27:47,902 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:47,903 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1868923003] [2022-11-03 03:27:47,903 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1868923003] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:47,903 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:47,903 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:27:47,904 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [636555008] [2022-11-03 03:27:47,904 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:47,904 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:27:47,905 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:47,905 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:27:47,905 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:27:47,906 INFO L87 Difference]: Start difference. First operand 604 states and 755 transitions. Second operand has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2022-11-03 03:27:48,087 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:48,088 INFO L93 Difference]: Finished difference Result 971 states and 1215 transitions. [2022-11-03 03:27:48,089 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:27:48,089 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) Word has length 56 [2022-11-03 03:27:48,091 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:48,094 INFO L225 Difference]: With dead ends: 971 [2022-11-03 03:27:48,094 INFO L226 Difference]: Without dead ends: 369 [2022-11-03 03:27:48,096 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:27:48,104 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 85 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 82 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 85 SdHoareTripleChecker+Valid, 120 SdHoareTripleChecker+Invalid, 86 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 82 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:48,105 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [85 Valid, 120 Invalid, 86 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 82 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:48,107 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 369 states. [2022-11-03 03:27:48,182 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 369 to 352. [2022-11-03 03:27:48,183 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 352 states, 239 states have (on average 1.2510460251046025) internal successors, (299), 261 states have internal predecessors, (299), 55 states have call successors, (55), 49 states have call predecessors, (55), 57 states have return successors, (78), 57 states have call predecessors, (78), 55 states have call successors, (78) [2022-11-03 03:27:48,186 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 352 states to 352 states and 432 transitions. [2022-11-03 03:27:48,188 INFO L78 Accepts]: Start accepts. Automaton has 352 states and 432 transitions. Word has length 56 [2022-11-03 03:27:48,188 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:48,189 INFO L495 AbstractCegarLoop]: Abstraction has 352 states and 432 transitions. [2022-11-03 03:27:48,189 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2022-11-03 03:27:48,189 INFO L276 IsEmpty]: Start isEmpty. Operand 352 states and 432 transitions. [2022-11-03 03:27:48,194 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2022-11-03 03:27:48,195 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:48,195 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:48,195 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-03 03:27:48,196 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:48,198 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:48,198 INFO L85 PathProgramCache]: Analyzing trace with hash -37876805, now seen corresponding path program 1 times [2022-11-03 03:27:48,199 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:48,199 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [100670531] [2022-11-03 03:27:48,199 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:48,199 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:48,253 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:48,471 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 17 proven. 4 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2022-11-03 03:27:48,472 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:48,472 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [100670531] [2022-11-03 03:27:48,475 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [100670531] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:27:48,475 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [683029433] [2022-11-03 03:27:48,476 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:48,476 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:27:48,476 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:27:48,482 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:27:48,494 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 03:27:48,657 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:48,661 INFO L263 TraceCheckSpWp]: Trace formula consists of 434 conjuncts, 4 conjunts are in the unsatisfiable core [2022-11-03 03:27:48,674 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:27:48,804 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 26 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:27:48,805 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-03 03:27:48,805 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [683029433] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:48,805 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-03 03:27:48,806 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [7] total 8 [2022-11-03 03:27:48,806 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2052156502] [2022-11-03 03:27:48,806 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:48,807 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:27:48,807 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:48,808 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:27:48,808 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:27:48,808 INFO L87 Difference]: Start difference. First operand 352 states and 432 transitions. Second operand has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (7), 3 states have call predecessors, (7), 3 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) [2022-11-03 03:27:48,935 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:48,935 INFO L93 Difference]: Finished difference Result 704 states and 863 transitions. [2022-11-03 03:27:48,936 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:27:48,936 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (7), 3 states have call predecessors, (7), 3 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) Word has length 60 [2022-11-03 03:27:48,937 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:48,939 INFO L225 Difference]: With dead ends: 704 [2022-11-03 03:27:48,939 INFO L226 Difference]: Without dead ends: 354 [2022-11-03 03:27:48,941 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 67 GetRequests, 61 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:27:48,942 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 31 mSDsluCounter, 48 mSDsCounter, 0 mSdLazyCounter, 41 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 31 SdHoareTripleChecker+Valid, 120 SdHoareTripleChecker+Invalid, 42 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 41 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:48,942 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [31 Valid, 120 Invalid, 42 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 41 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:48,944 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 354 states. [2022-11-03 03:27:48,986 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 354 to 352. [2022-11-03 03:27:48,988 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 352 states, 239 states have (on average 1.2301255230125523) internal successors, (294), 261 states have internal predecessors, (294), 55 states have call successors, (55), 49 states have call predecessors, (55), 57 states have return successors, (70), 57 states have call predecessors, (70), 55 states have call successors, (70) [2022-11-03 03:27:48,990 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 352 states to 352 states and 419 transitions. [2022-11-03 03:27:48,990 INFO L78 Accepts]: Start accepts. Automaton has 352 states and 419 transitions. Word has length 60 [2022-11-03 03:27:48,991 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:48,991 INFO L495 AbstractCegarLoop]: Abstraction has 352 states and 419 transitions. [2022-11-03 03:27:48,991 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (7), 3 states have call predecessors, (7), 3 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) [2022-11-03 03:27:48,992 INFO L276 IsEmpty]: Start isEmpty. Operand 352 states and 419 transitions. [2022-11-03 03:27:48,993 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2022-11-03 03:27:48,993 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:48,994 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:49,042 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-03 03:27:49,212 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:27:49,212 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:49,213 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:49,213 INFO L85 PathProgramCache]: Analyzing trace with hash 479242136, now seen corresponding path program 1 times [2022-11-03 03:27:49,213 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:49,213 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1469522970] [2022-11-03 03:27:49,213 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:49,214 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:49,238 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:49,767 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 18 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 03:27:49,767 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:49,767 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1469522970] [2022-11-03 03:27:49,768 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1469522970] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:49,768 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:49,768 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-11-03 03:27:49,768 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1543920748] [2022-11-03 03:27:49,769 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:49,770 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-11-03 03:27:49,770 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:49,771 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-11-03 03:27:49,771 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=66, Unknown=0, NotChecked=0, Total=90 [2022-11-03 03:27:49,772 INFO L87 Difference]: Start difference. First operand 352 states and 419 transitions. Second operand has 10 states, 9 states have (on average 5.0) internal successors, (45), 9 states have internal predecessors, (45), 5 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 5 states have call successors, (7) [2022-11-03 03:27:50,836 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:50,836 INFO L93 Difference]: Finished difference Result 926 states and 1130 transitions. [2022-11-03 03:27:50,837 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2022-11-03 03:27:50,837 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 9 states have (on average 5.0) internal successors, (45), 9 states have internal predecessors, (45), 5 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 5 states have call successors, (7) Word has length 62 [2022-11-03 03:27:50,837 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:50,841 INFO L225 Difference]: With dead ends: 926 [2022-11-03 03:27:50,841 INFO L226 Difference]: Without dead ends: 576 [2022-11-03 03:27:50,843 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 21 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 103 ImplicationChecksByTransitivity, 0.5s TimeCoverageRelationStatistics Valid=130, Invalid=376, Unknown=0, NotChecked=0, Total=506 [2022-11-03 03:27:50,844 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 268 mSDsluCounter, 307 mSDsCounter, 0 mSdLazyCounter, 435 mSolverCounterSat, 124 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 277 SdHoareTripleChecker+Valid, 349 SdHoareTripleChecker+Invalid, 559 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 124 IncrementalHoareTripleChecker+Valid, 435 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:50,844 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [277 Valid, 349 Invalid, 559 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [124 Valid, 435 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-03 03:27:50,846 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 576 states. [2022-11-03 03:27:50,938 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 576 to 462. [2022-11-03 03:27:50,940 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 462 states, 321 states have (on average 1.2274143302180685) internal successors, (394), 345 states have internal predecessors, (394), 69 states have call successors, (69), 63 states have call predecessors, (69), 71 states have return successors, (84), 71 states have call predecessors, (84), 69 states have call successors, (84) [2022-11-03 03:27:50,942 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 462 states to 462 states and 547 transitions. [2022-11-03 03:27:50,943 INFO L78 Accepts]: Start accepts. Automaton has 462 states and 547 transitions. Word has length 62 [2022-11-03 03:27:50,943 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:50,943 INFO L495 AbstractCegarLoop]: Abstraction has 462 states and 547 transitions. [2022-11-03 03:27:50,944 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 9 states have (on average 5.0) internal successors, (45), 9 states have internal predecessors, (45), 5 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 5 states have call successors, (7) [2022-11-03 03:27:50,944 INFO L276 IsEmpty]: Start isEmpty. Operand 462 states and 547 transitions. [2022-11-03 03:27:50,946 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-03 03:27:50,946 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:50,946 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:50,947 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-03 03:27:50,947 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:50,948 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:50,948 INFO L85 PathProgramCache]: Analyzing trace with hash -517691219, now seen corresponding path program 1 times [2022-11-03 03:27:50,948 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:50,948 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1506465292] [2022-11-03 03:27:50,948 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:50,949 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:50,974 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:51,128 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 7 proven. 0 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-03 03:27:51,129 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:51,129 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1506465292] [2022-11-03 03:27:51,130 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1506465292] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:27:51,130 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:27:51,130 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:27:51,130 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [867984725] [2022-11-03 03:27:51,130 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:27:51,132 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:27:51,133 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:27:51,133 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:27:51,133 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:27:51,134 INFO L87 Difference]: Start difference. First operand 462 states and 547 transitions. Second operand has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (8), 1 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2022-11-03 03:27:51,271 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:27:51,272 INFO L93 Difference]: Finished difference Result 664 states and 790 transitions. [2022-11-03 03:27:51,272 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-03 03:27:51,273 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (8), 1 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) Word has length 65 [2022-11-03 03:27:51,275 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:27:51,278 INFO L225 Difference]: With dead ends: 664 [2022-11-03 03:27:51,279 INFO L226 Difference]: Without dead ends: 431 [2022-11-03 03:27:51,280 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 03:27:51,281 INFO L413 NwaCegarLoop]: 60 mSDtfsCounter, 47 mSDsluCounter, 123 mSDsCounter, 0 mSdLazyCounter, 52 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 47 SdHoareTripleChecker+Valid, 163 SdHoareTripleChecker+Invalid, 54 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 52 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:27:51,283 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [47 Valid, 163 Invalid, 54 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 52 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:27:51,284 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 431 states. [2022-11-03 03:27:51,367 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 431 to 414. [2022-11-03 03:27:51,369 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 414 states, 287 states have (on average 1.2125435540069687) internal successors, (348), 309 states have internal predecessors, (348), 62 states have call successors, (62), 57 states have call predecessors, (62), 64 states have return successors, (72), 63 states have call predecessors, (72), 62 states have call successors, (72) [2022-11-03 03:27:51,371 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 414 states to 414 states and 482 transitions. [2022-11-03 03:27:51,372 INFO L78 Accepts]: Start accepts. Automaton has 414 states and 482 transitions. Word has length 65 [2022-11-03 03:27:51,372 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:27:51,373 INFO L495 AbstractCegarLoop]: Abstraction has 414 states and 482 transitions. [2022-11-03 03:27:51,373 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (8), 1 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2022-11-03 03:27:51,373 INFO L276 IsEmpty]: Start isEmpty. Operand 414 states and 482 transitions. [2022-11-03 03:27:51,375 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2022-11-03 03:27:51,375 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:27:51,376 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:27:51,376 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-11-03 03:27:51,376 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:27:51,377 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:27:51,377 INFO L85 PathProgramCache]: Analyzing trace with hash 268936039, now seen corresponding path program 1 times [2022-11-03 03:27:51,377 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:27:51,377 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1398936608] [2022-11-03 03:27:51,378 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:51,378 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:27:51,402 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:51,650 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 11 proven. 6 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-03 03:27:51,650 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:27:51,650 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1398936608] [2022-11-03 03:27:51,650 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1398936608] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:27:51,651 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [995194042] [2022-11-03 03:27:51,651 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:27:51,651 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:27:51,651 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:27:51,652 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:27:51,655 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 03:27:51,788 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:27:51,791 INFO L263 TraceCheckSpWp]: Trace formula consists of 447 conjuncts, 26 conjunts are in the unsatisfiable core [2022-11-03 03:27:51,795 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:27:52,071 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 15 proven. 11 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:27:52,071 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:27:52,526 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 12 proven. 6 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 03:27:52,526 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [995194042] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:27:52,527 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [544799079] [2022-11-03 03:27:52,553 INFO L159 IcfgInterpreter]: Started Sifa with 45 locations of interest [2022-11-03 03:27:52,553 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:27:52,559 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:27:52,566 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:27:52,567 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:28:03,603 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 52 for LOIs [2022-11-03 03:28:03,616 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-03 03:28:03,999 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 42 for LOIs [2022-11-03 03:28:04,124 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 47 for LOIs [2022-11-03 03:28:04,136 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 50 for LOIs [2022-11-03 03:28:04,143 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 43 for LOIs [2022-11-03 03:28:04,150 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:28:17,669 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '12921#(and (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~4#1|) (= ~head~0.offset 0) (<= |timeShift_isPumpRunning_#res#1| 2147483647) (<= |timeShift___utac_acc__Specification2_spec__2_~tmp~0#1| 1) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification2_spec__2_~tmp___0~0#1|) (= 1 ~systemActive~0) (= |timeShift___utac_acc__Specification2_spec__2_~tmp~0#1| ~methaneLevelCritical~0) (<= 0 ~methAndRunningLastTime~0) (<= 0 |old(~methAndRunningLastTime~0)|) (<= |old(~methAndRunningLastTime~0)| 1) (<= 0 ~methaneLevelCritical~0) (= ~head~0.base 0) (not (= |timeShift___utac_acc__Specification2_spec__2_~tmp~0#1| 0)) (= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~4#1|) (<= 0 (+ |timeShift_isPumpRunning_#res#1| 2147483648)) (not (= |timeShift___utac_acc__Specification2_spec__2_~tmp___0~0#1| 0)) (not (= ~methAndRunningLastTime~0 0)) (<= ~methAndRunningLastTime~0 1) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:28:17,669 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:28:17,669 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:28:17,669 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 9, 11] total 20 [2022-11-03 03:28:17,670 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [51600360] [2022-11-03 03:28:17,670 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:28:17,671 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-03 03:28:17,671 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:28:17,671 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-03 03:28:17,673 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=254, Invalid=2196, Unknown=0, NotChecked=0, Total=2450 [2022-11-03 03:28:17,673 INFO L87 Difference]: Start difference. First operand 414 states and 482 transitions. Second operand has 20 states, 13 states have (on average 7.230769230769231) internal successors, (94), 16 states have internal predecessors, (94), 8 states have call successors, (24), 8 states have call predecessors, (24), 11 states have return successors, (23), 9 states have call predecessors, (23), 8 states have call successors, (23) [2022-11-03 03:28:19,592 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:28:19,593 INFO L93 Difference]: Finished difference Result 1018 states and 1214 transitions. [2022-11-03 03:28:19,593 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 24 states. [2022-11-03 03:28:19,594 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 13 states have (on average 7.230769230769231) internal successors, (94), 16 states have internal predecessors, (94), 8 states have call successors, (24), 8 states have call predecessors, (24), 11 states have return successors, (23), 9 states have call predecessors, (23), 8 states have call successors, (23) Word has length 70 [2022-11-03 03:28:19,594 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:28:19,599 INFO L225 Difference]: With dead ends: 1018 [2022-11-03 03:28:19,599 INFO L226 Difference]: Without dead ends: 833 [2022-11-03 03:28:19,602 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 244 GetRequests, 162 SyntacticMatches, 15 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1886 ImplicationChecksByTransitivity, 14.3s TimeCoverageRelationStatistics Valid=463, Invalid=4229, Unknown=0, NotChecked=0, Total=4692 [2022-11-03 03:28:19,603 INFO L413 NwaCegarLoop]: 125 mSDtfsCounter, 570 mSDsluCounter, 539 mSDsCounter, 0 mSdLazyCounter, 1336 mSolverCounterSat, 312 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 578 SdHoareTripleChecker+Valid, 558 SdHoareTripleChecker+Invalid, 1648 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 312 IncrementalHoareTripleChecker+Valid, 1336 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.2s IncrementalHoareTripleChecker+Time [2022-11-03 03:28:19,603 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [578 Valid, 558 Invalid, 1648 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [312 Valid, 1336 Invalid, 0 Unknown, 0 Unchecked, 1.2s Time] [2022-11-03 03:28:19,605 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 833 states. [2022-11-03 03:28:19,712 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 833 to 622. [2022-11-03 03:28:19,717 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 622 states, 430 states have (on average 1.216279069767442) internal successors, (523), 465 states have internal predecessors, (523), 94 states have call successors, (94), 88 states have call predecessors, (94), 97 states have return successors, (107), 95 states have call predecessors, (107), 94 states have call successors, (107) [2022-11-03 03:28:19,721 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 622 states to 622 states and 724 transitions. [2022-11-03 03:28:19,722 INFO L78 Accepts]: Start accepts. Automaton has 622 states and 724 transitions. Word has length 70 [2022-11-03 03:28:19,722 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:28:19,723 INFO L495 AbstractCegarLoop]: Abstraction has 622 states and 724 transitions. [2022-11-03 03:28:19,723 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 13 states have (on average 7.230769230769231) internal successors, (94), 16 states have internal predecessors, (94), 8 states have call successors, (24), 8 states have call predecessors, (24), 11 states have return successors, (23), 9 states have call predecessors, (23), 8 states have call successors, (23) [2022-11-03 03:28:19,723 INFO L276 IsEmpty]: Start isEmpty. Operand 622 states and 724 transitions. [2022-11-03 03:28:19,725 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 74 [2022-11-03 03:28:19,726 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:28:19,726 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:28:19,775 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-11-03 03:28:19,941 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-03 03:28:19,942 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:28:19,942 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:28:19,942 INFO L85 PathProgramCache]: Analyzing trace with hash -906160309, now seen corresponding path program 1 times [2022-11-03 03:28:19,942 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:28:19,942 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1923032840] [2022-11-03 03:28:19,943 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:28:19,943 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:28:19,967 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:28:20,315 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 6 proven. 16 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-03 03:28:20,315 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:28:20,315 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1923032840] [2022-11-03 03:28:20,316 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1923032840] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:28:20,316 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [525477297] [2022-11-03 03:28:20,316 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:28:20,316 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:28:20,316 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:28:20,318 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:28:20,349 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 03:28:20,451 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:28:20,453 INFO L263 TraceCheckSpWp]: Trace formula consists of 453 conjuncts, 23 conjunts are in the unsatisfiable core [2022-11-03 03:28:20,457 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:28:20,553 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-11-03 03:28:20,554 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-03 03:28:20,554 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [525477297] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:28:20,554 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-03 03:28:20,554 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [13] total 16 [2022-11-03 03:28:20,554 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [201277198] [2022-11-03 03:28:20,555 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:28:20,555 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-03 03:28:20,555 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:28:20,556 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-03 03:28:20,556 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=35, Invalid=205, Unknown=0, NotChecked=0, Total=240 [2022-11-03 03:28:20,556 INFO L87 Difference]: Start difference. First operand 622 states and 724 transitions. Second operand has 9 states, 7 states have (on average 6.142857142857143) internal successors, (43), 7 states have internal predecessors, (43), 2 states have call successors, (9), 2 states have call predecessors, (9), 4 states have return successors, (9), 4 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-03 03:28:21,010 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:28:21,011 INFO L93 Difference]: Finished difference Result 1183 states and 1391 transitions. [2022-11-03 03:28:21,011 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 03:28:21,012 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 7 states have (on average 6.142857142857143) internal successors, (43), 7 states have internal predecessors, (43), 2 states have call successors, (9), 2 states have call predecessors, (9), 4 states have return successors, (9), 4 states have call predecessors, (9), 2 states have call successors, (9) Word has length 73 [2022-11-03 03:28:21,012 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:28:21,013 INFO L225 Difference]: With dead ends: 1183 [2022-11-03 03:28:21,013 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 03:28:21,015 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 98 GetRequests, 77 SyntacticMatches, 0 SemanticMatches, 21 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 54 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=76, Invalid=430, Unknown=0, NotChecked=0, Total=506 [2022-11-03 03:28:21,016 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 54 mSDsluCounter, 413 mSDsCounter, 0 mSdLazyCounter, 311 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 59 SdHoareTripleChecker+Valid, 388 SdHoareTripleChecker+Invalid, 320 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 311 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 03:28:21,016 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [59 Valid, 388 Invalid, 320 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 311 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 03:28:21,017 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 03:28:21,017 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 03:28:21,017 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 03:28:21,018 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 03:28:21,018 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 73 [2022-11-03 03:28:21,018 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:28:21,018 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 03:28:21,019 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 7 states have (on average 6.142857142857143) internal successors, (43), 7 states have internal predecessors, (43), 2 states have call successors, (9), 2 states have call predecessors, (9), 4 states have return successors, (9), 4 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-03 03:28:21,019 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 03:28:21,019 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 03:28:21,022 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 03:28:21,075 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 03:28:21,238 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:28:21,241 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 03:28:31,044 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 362 369) the Hoare annotation is: (let ((.cse2 (= 0 ~systemActive~0))) (let ((.cse0 (and (<= 1 ~pumpRunning~0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not .cse2))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 1)) .cse2)))) [2022-11-03 03:28:31,045 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 362 369) no Hoare annotation was computed. [2022-11-03 03:28:31,045 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 295 301) no Hoare annotation was computed. [2022-11-03 03:28:31,045 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 295 301) the Hoare annotation is: true [2022-11-03 03:28:31,052 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 124 135) the Hoare annotation is: (let ((.cse4 (not (= 0 ~systemActive~0))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= ~methaneLevelCritical~0 1)) (.cse2 (not (= |old(~methaneLevelCritical~0)| 1))) (.cse3 (not (= ~methAndRunningLastTime~0 0))) (.cse5 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse7 (not (= 1 ~systemActive~0))) (.cse6 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse8 (not (<= 1 ~pumpRunning~0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse0 .cse6 .cse3 .cse4) (or .cse5 .cse0 .cse7 .cse6 .cse3) (or .cse7 .cse8 .cse1 .cse2) (or .cse0 .cse7 .cse1 .cse2 .cse3) (or .cse5 .cse7 .cse6 .cse8))) [2022-11-03 03:28:31,052 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 124 135) no Hoare annotation was computed. [2022-11-03 03:28:31,052 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 845 874) no Hoare annotation was computed. [2022-11-03 03:28:31,053 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 845 874) the Hoare annotation is: true [2022-11-03 03:28:31,053 INFO L899 garLoopResultBuilder]: For program point L859(lines 859 863) no Hoare annotation was computed. [2022-11-03 03:28:31,053 INFO L902 garLoopResultBuilder]: At program point L859-1(lines 859 863) the Hoare annotation is: true [2022-11-03 03:28:31,054 INFO L902 garLoopResultBuilder]: At program point L855-2(lines 855 869) the Hoare annotation is: true [2022-11-03 03:28:31,054 INFO L902 garLoopResultBuilder]: At program point L851(line 851) the Hoare annotation is: true [2022-11-03 03:28:31,054 INFO L899 garLoopResultBuilder]: For program point L851-1(line 851) no Hoare annotation was computed. [2022-11-03 03:28:31,054 INFO L902 garLoopResultBuilder]: At program point L870(lines 845 874) the Hoare annotation is: true [2022-11-03 03:28:31,054 INFO L899 garLoopResultBuilder]: For program point L866(line 866) no Hoare annotation was computed. [2022-11-03 03:28:31,055 INFO L899 garLoopResultBuilder]: For program point L275-1(lines 274 293) no Hoare annotation was computed. [2022-11-03 03:28:31,055 INFO L899 garLoopResultBuilder]: For program point L337(lines 337 345) no Hoare annotation was computed. [2022-11-03 03:28:31,055 INFO L899 garLoopResultBuilder]: For program point L333(lines 333 350) no Hoare annotation was computed. [2022-11-03 03:28:31,056 INFO L895 garLoopResultBuilder]: At program point L375(line 375) the Hoare annotation is: (let ((.cse8 (= ~methAndRunningLastTime~0 0)) (.cse2 (not (= 0 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (= 1 ~systemActive~0))) (.cse5 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6) (or .cse7 .cse8 .cse4 .cse5 .cse1) (or .cse7 .cse8 .cse4 .cse5 .cse6) (or .cse0 .cse6 .cse2) (or .cse0 .cse7 .cse4 .cse6) (or .cse0 .cse7 .cse4 .cse1) (or .cse3 .cse4 .cse5 .cse1))) [2022-11-03 03:28:31,056 INFO L895 garLoopResultBuilder]: At program point L375-1(line 375) the Hoare annotation is: (let ((.cse7 (= ~methAndRunningLastTime~0 0)) (.cse5 (not (= 0 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse3 (not (= ~methaneLevelCritical~0 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isMethaneAlarm_#t~ret17#1| ~methaneLevelCritical~0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse3 .cse5) (or .cse6 .cse7 .cse0 .cse1 .cse3) (or .cse6 .cse7 .cse0 .cse1 .cse8) (or .cse4 .cse8 .cse5) (or .cse4 .cse6 .cse0 .cse8) (or .cse4 .cse6 .cse0 .cse3) (or .cse0 .cse1 .cse8 .cse2))) [2022-11-03 03:28:31,057 INFO L899 garLoopResultBuilder]: For program point L74(lines 74 84) no Hoare annotation was computed. [2022-11-03 03:28:31,057 INFO L895 garLoopResultBuilder]: At program point L70(lines 70 87) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse17 (= ~waterLevel~0 1))) (let ((.cse6 (= ~pumpRunning~0 0)) (.cse7 (or .cse0 .cse16 .cse17))) (let ((.cse2 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~0#1| 0)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= 0 ~systemActive~0))) (.cse4 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse14 (and .cse6 .cse7)) (.cse8 (<= 1 ~pumpRunning~0)) (.cse9 (not .cse17)) (.cse13 (= ~methAndRunningLastTime~0 0)) (.cse10 (or .cse0 .cse16)) (.cse11 (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0)) (.cse5 (not (= 1 ~systemActive~0))) (.cse12 (not (<= 1 |old(~pumpRunning~0)|))) (.cse15 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse5 .cse1 (and .cse6 .cse7 .cse2) (and .cse8 .cse9 .cse2 .cse10)) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2 .cse11) .cse5 .cse12 .cse1) (or .cse0 .cse4 .cse13 .cse5 .cse1) (or .cse4 .cse13 .cse5 .cse12 .cse1) (or .cse0 .cse1 .cse14 .cse3) (or .cse0 .cse4 .cse13 .cse1 .cse3) (or .cse0 .cse15 .cse14 .cse3) (or .cse0 .cse4 .cse5 .cse15 .cse14 (and .cse8 .cse9 .cse13 .cse10)) (or (and .cse6 .cse11) .cse5 .cse12 .cse15))))) [2022-11-03 03:28:31,058 INFO L895 garLoopResultBuilder]: At program point L70-1(lines 62 90) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse17 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse11 (= ~waterLevel~0 1)) (.cse13 (= 1 ~systemActive~0)) (.cse6 (= 0 ~systemActive~0))) (let ((.cse16 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse15 (not (= ~methaneLevelCritical~0 1))) (.cse8 (not .cse6)) (.cse9 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse14 (not .cse13)) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (or .cse0 .cse17 .cse11)) (.cse10 (<= 1 ~pumpRunning~0)) (.cse3 (= ~methAndRunningLastTime~0 0)) (.cse5 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~0#1| 0)) (.cse12 (or .cse0 .cse17))) (and (or .cse0 (and .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) .cse7 .cse8) (or .cse0 .cse9 (and .cse10 (not .cse11) .cse12) (and .cse1 .cse2 .cse3 .cse4 .cse13) .cse14 .cse15) (or .cse0 .cse9 (not (= |old(~waterLevel~0)| 1)) .cse14 .cse7 (and .cse1 .cse2 .cse3 .cse13)) (or (and .cse2 .cse3 (= |timeShift_processEnvironment_~tmp~3#1| 1)) .cse14 .cse16 .cse15) (or (and .cse1 .cse3 .cse5 (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0)) .cse14 .cse16 .cse7) (or .cse0 (and .cse1 .cse2 .cse3 .cse4 .cse6) .cse15 .cse8) (or .cse0 .cse9 .cse14 .cse7 (and .cse2 .cse3 .cse4 .cse5) (and .cse10 .cse3 .cse5 .cse12))))) [2022-11-03 03:28:31,058 INFO L895 garLoopResultBuilder]: At program point L343(line 343) the Hoare annotation is: (let ((.cse2 (not (= 0 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0))) (or .cse6 (= ~methAndRunningLastTime~0 0) .cse3 .cse4 .cse5) (or .cse0 .cse5 .cse2) (or .cse0 .cse6 .cse3 .cse5) (or .cse3 .cse4 .cse1) (or .cse0 .cse6 .cse3 .cse1))) [2022-11-03 03:28:31,058 INFO L895 garLoopResultBuilder]: At program point L339(line 339) the Hoare annotation is: (let ((.cse5 (not (= 0 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5) (or .cse6 (= ~methAndRunningLastTime~0 0) .cse0 .cse1 .cse4) (or .cse3 .cse2 .cse5) (or .cse3 .cse6 .cse0 .cse2) (or .cse3 .cse6 .cse0 .cse4) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0)) .cse4))) [2022-11-03 03:28:31,059 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 81) no Hoare annotation was computed. [2022-11-03 03:28:31,060 INFO L895 garLoopResultBuilder]: At program point L839(line 839) the Hoare annotation is: (let ((.cse5 (not (= 0 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5) (or .cse3 .cse2 .cse5) (or .cse3 .cse6 .cse0 .cse2) (or .cse0 .cse1 .cse4) (or .cse3 .cse6 .cse0 .cse4))) [2022-11-03 03:28:31,060 INFO L895 garLoopResultBuilder]: At program point L348(line 348) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0)))) (let ((.cse4 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse6 (and (= ~pumpRunning~0 0) (= ~methAndRunningLastTime~0 0) (or .cse3 (= |old(~waterLevel~0)| ~waterLevel~0) (= ~waterLevel~0 1)))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse7 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 |old(~pumpRunning~0)|))) (.cse5 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0 .cse5 .cse6) (or .cse3 .cse5 .cse7) (or .cse3 .cse4 .cse0 .cse2 .cse6) (or .cse3 .cse2 .cse7) (or .cse0 .cse1 .cse5)))) [2022-11-03 03:28:31,061 INFO L895 garLoopResultBuilder]: At program point L348-1(lines 329 353) the Hoare annotation is: (let ((.cse11 (= ~pumpRunning~0 0)) (.cse13 (= ~waterLevel~0 1)) (.cse10 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse12 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse6 (not (= 0 ~systemActive~0))) (.cse1 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse4 (and (<= 1 ~pumpRunning~0) (not .cse13) .cse10 (or .cse0 .cse12))) (.cse5 (and .cse11 .cse10 (or .cse0 .cse12 .cse13))) (.cse9 (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse7 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse0 .cse3 .cse6) (or .cse2 .cse7 .cse8 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse9)) (or .cse1 .cse10 .cse2 .cse7 .cse3) (or .cse1 .cse10 .cse2 .cse7 .cse8) (or .cse0 .cse8 .cse6) (or .cse0 .cse1 .cse2 .cse8 .cse4 .cse5) (or (and .cse11 .cse9) .cse2 .cse7 .cse3)))) [2022-11-03 03:28:31,061 INFO L899 garLoopResultBuilder]: For program point L282-1(lines 282 288) no Hoare annotation was computed. [2022-11-03 03:28:31,062 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 271 294) the Hoare annotation is: (let ((.cse13 (<= 1 ~pumpRunning~0)) (.cse12 (= 1 ~systemActive~0)) (.cse9 (= ~methAndRunningLastTime~0 0)) (.cse14 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse16 (= ~pumpRunning~0 0)) (.cse15 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse17 (= 0 ~systemActive~0))) (let ((.cse7 (and .cse14 .cse16 .cse15 .cse17)) (.cse8 (not .cse17)) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and .cse16 .cse9 .cse15)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse0 (and .cse13 .cse14 .cse12 .cse15)) (.cse4 (and .cse13 .cse14 .cse9 .cse12 .cse15)) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse1 (not .cse12)) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse11 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse1 .cse2 .cse3) (or .cse6 .cse7 .cse3 .cse8) (or .cse6 .cse5 .cse9 .cse3 .cse8) (or .cse6 .cse5 .cse1 .cse10 .cse11) (or .cse6 .cse7 .cse11 .cse8) (or .cse6 .cse5 .cse1 .cse10 .cse3) (or .cse0 .cse1 .cse2 .cse11) (or .cse4 .cse5 .cse1 .cse2 .cse11)))) [2022-11-03 03:28:31,062 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 271 294) no Hoare annotation was computed. [2022-11-03 03:28:31,062 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 839) no Hoare annotation was computed. [2022-11-03 03:28:31,063 INFO L895 garLoopResultBuilder]: At program point L68(line 68) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse15 (= ~waterLevel~0 1))) (let ((.cse12 (= ~methAndRunningLastTime~0 0)) (.cse10 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (= ~pumpRunning~0 0)) (.cse14 (or .cse0 .cse16 .cse15)) (.cse17 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse10 .cse13 .cse14 .cse17)) (.cse3 (not .cse17)) (.cse4 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse6 (and (<= 1 ~pumpRunning~0) (not .cse15) .cse12 (or .cse0 .cse16))) (.cse7 (and .cse13 .cse12 .cse14)) (.cse11 (= |timeShift_processEnvironment_~tmp~3#1| ~methaneLevelCritical~0)) (.cse5 (not (= 1 ~systemActive~0))) (.cse8 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse5 .cse2 .cse6 .cse7) (or .cse5 .cse8 .cse9 (and .cse10 .cse11)) (or .cse4 .cse12 .cse5 .cse8 .cse2) (or .cse4 .cse12 .cse5 .cse8 .cse9) (or .cse0 .cse4 .cse12 .cse9 .cse3) (or .cse0 .cse9 .cse1 .cse3) (or .cse0 .cse4 .cse5 .cse9 .cse6 .cse7) (or (and .cse13 .cse11) .cse5 .cse8 .cse2))))) [2022-11-03 03:28:31,063 INFO L899 garLoopResultBuilder]: For program point L68-1(line 68) no Hoare annotation was computed. [2022-11-03 03:28:31,063 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 136 144) the Hoare annotation is: true [2022-11-03 03:28:31,063 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 136 144) no Hoare annotation was computed. [2022-11-03 03:28:31,063 INFO L902 garLoopResultBuilder]: At program point L259(lines 196 263) the Hoare annotation is: true [2022-11-03 03:28:31,064 INFO L899 garLoopResultBuilder]: For program point L226(lines 226 232) no Hoare annotation was computed. [2022-11-03 03:28:31,064 INFO L899 garLoopResultBuilder]: For program point L226-1(lines 226 232) no Hoare annotation was computed. [2022-11-03 03:28:31,064 INFO L899 garLoopResultBuilder]: For program point L449(lines 449 455) no Hoare annotation was computed. [2022-11-03 03:28:31,064 INFO L895 garLoopResultBuilder]: At program point L449-1(lines 449 455) the Hoare annotation is: (let ((.cse0 (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse1 .cse2 (not (= 0 ~systemActive~0))) (and .cse1 (= ~methAndRunningLastTime~0 0) .cse2))))) (or (and (= ~methaneLevelCritical~0 0) .cse0) (and (= ~methaneLevelCritical~0 1) .cse0))) [2022-11-03 03:28:31,065 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 03:28:31,065 INFO L895 garLoopResultBuilder]: At program point L218(line 218) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= ~methAndRunningLastTime~0 0)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse7 (= 0 ~systemActive~0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse6 .cse3 .cse7) (and .cse0 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse2 .cse3 .cse7))) [2022-11-03 03:28:31,065 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 03:28:31,065 INFO L895 garLoopResultBuilder]: At program point L256(lines 205 257) the Hoare annotation is: false [2022-11-03 03:28:31,065 INFO L899 garLoopResultBuilder]: For program point L244(lines 244 250) no Hoare annotation was computed. [2022-11-03 03:28:31,066 INFO L895 garLoopResultBuilder]: At program point L244-2(lines 236 251) the Hoare annotation is: (let ((.cse5 (= ~methAndRunningLastTime~0 0)) (.cse0 (<= 1 ~pumpRunning~0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse7 (= 0 ~systemActive~0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse6 .cse1 .cse3) (and .cse4 .cse6 .cse3 .cse7) (and .cse0 .cse6 .cse1 .cse3) (and .cse4 .cse2 .cse3 .cse7))) [2022-11-03 03:28:31,066 INFO L899 garLoopResultBuilder]: For program point L207(lines 206 255) no Hoare annotation was computed. [2022-11-03 03:28:31,066 INFO L895 garLoopResultBuilder]: At program point L236(lines 236 251) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= ~methAndRunningLastTime~0 0)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse7 (= 0 ~systemActive~0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse6 .cse3 .cse7) (and .cse0 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse2 .cse3 .cse7))) [2022-11-03 03:28:31,067 INFO L895 garLoopResultBuilder]: At program point L228(line 228) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= ~methAndRunningLastTime~0 0)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse7 (= 0 ~systemActive~0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse6 .cse3 .cse7) (and .cse0 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse2 .cse3 .cse7))) [2022-11-03 03:28:31,067 INFO L895 garLoopResultBuilder]: At program point L451(line 451) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~methaneLevelCritical~0 1) .cse1 .cse2) (and .cse0 (= ~methaneLevelCritical~0 0) .cse1 .cse2))) [2022-11-03 03:28:31,067 INFO L895 garLoopResultBuilder]: At program point L930(lines 930 937) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methAndRunningLastTime~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-03 03:28:31,067 INFO L902 garLoopResultBuilder]: At program point L930-2(lines 930 937) the Hoare annotation is: true [2022-11-03 03:28:31,068 INFO L895 garLoopResultBuilder]: At program point L253(lines 206 255) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (= ~methAndRunningLastTime~0 0)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse7 (= 0 ~systemActive~0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse1 .cse2 .cse3) (and .cse4 .cse5 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse6 .cse3 .cse7) (and .cse0 .cse6 .cse1 .cse3) (and .cse4 .cse5 .cse2 .cse3 .cse7))) [2022-11-03 03:28:31,068 INFO L899 garLoopResultBuilder]: For program point L216(lines 216 222) no Hoare annotation was computed. [2022-11-03 03:28:31,068 INFO L899 garLoopResultBuilder]: For program point L216-1(lines 216 222) no Hoare annotation was computed. [2022-11-03 03:28:31,068 INFO L899 garLoopResultBuilder]: For program point L322-1(lines 303 327) no Hoare annotation was computed. [2022-11-03 03:28:31,069 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 303 327) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= ~methAndRunningLastTime~0 0)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 1)) .cse3) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2 (not (<= 1 |old(~pumpRunning~0)|)) .cse4) (or .cse0 .cse1 .cse2 .cse4 .cse3))) [2022-11-03 03:28:31,069 INFO L895 garLoopResultBuilder]: At program point L317(line 317) the Hoare annotation is: (let ((.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse7 (= ~pumpRunning~0 0)) (.cse0 (not (= ~waterLevel~0 1))) (.cse2 (and (<= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0) (< 0 (+ |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 1)))) (.cse5 (not (= ~methAndRunningLastTime~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse3 (not (<= 1 |old(~pumpRunning~0)|)) .cse6) (or .cse1 .cse7 .cse3 .cse4 .cse5) (or .cse1 .cse3 .cse6 (and .cse7 (or .cse0 .cse2)) .cse5))) [2022-11-03 03:28:31,070 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 303 327) no Hoare annotation was computed. [2022-11-03 03:28:31,070 INFO L895 garLoopResultBuilder]: At program point L311(lines 311 319) the Hoare annotation is: (let ((.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse7 (= ~pumpRunning~0 0)) (.cse0 (not (= ~waterLevel~0 1))) (.cse2 (and (<= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0) (< 0 (+ |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 1)))) (.cse5 (not (= ~methAndRunningLastTime~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse3 (not (<= 1 |old(~pumpRunning~0)|)) .cse6) (or .cse1 .cse7 .cse3 .cse4 .cse5) (or .cse1 .cse3 .cse6 (and .cse7 (or .cse0 .cse2)) .cse5))) [2022-11-03 03:28:31,071 INFO L895 garLoopResultBuilder]: At program point L307(lines 307 324) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= ~methAndRunningLastTime~0 0)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 1)) .cse3) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2 (not (<= 1 |old(~pumpRunning~0)|)) .cse4) (or .cse0 .cse1 .cse2 .cse4 .cse3))) [2022-11-03 03:28:31,071 INFO L895 garLoopResultBuilder]: At program point L322(line 322) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~methAndRunningLastTime~0 0)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 1)) .cse2) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 (not (<= 1 |old(~pumpRunning~0)|)) .cse3) (or .cse0 .cse1 .cse3 .cse2))) [2022-11-03 03:28:31,071 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 112 123) no Hoare annotation was computed. [2022-11-03 03:28:31,072 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 112 123) the Hoare annotation is: (let ((.cse11 (= ~methAndRunningLastTime~0 0)) (.cse10 (= ~pumpRunning~0 0)) (.cse13 (<= 1 ~pumpRunning~0)) (.cse12 (= 1 ~systemActive~0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse4 (not (= 0 ~systemActive~0))) (.cse6 (and .cse13 .cse12 .cse2)) (.cse8 (not .cse13)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not .cse10)) (.cse7 (not .cse12)) (.cse5 (not (= ~methaneLevelCritical~0 1))) (.cse3 (not .cse11)) (.cse9 (and .cse10 .cse11 .cse12 .cse2))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse2 .cse3 .cse4) (or .cse6 .cse7 .cse8 .cse5) (or .cse6 .cse7 .cse1 .cse8) (or .cse0 .cse7 .cse1 .cse3 .cse9) (or .cse0 .cse7 .cse5 .cse3 .cse9)))) [2022-11-03 03:28:31,076 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:28:31,079 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 03:28:31,150 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 03:28:31 BoogieIcfgContainer [2022-11-03 03:28:31,154 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 03:28:31,155 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 03:28:31,155 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 03:28:31,156 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 03:28:31,156 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:27:44" (3/4) ... [2022-11-03 03:28:31,160 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 03:28:31,167 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-03 03:28:31,168 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 03:28:31,168 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 03:28:31,168 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 03:28:31,168 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 03:28:31,168 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-03 03:28:31,169 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:28:31,169 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 03:28:31,188 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 71 nodes and edges [2022-11-03 03:28:31,188 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 25 nodes and edges [2022-11-03 03:28:31,189 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 13 nodes and edges [2022-11-03 03:28:31,189 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 03:28:31,190 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 03:28:31,191 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:28:31,191 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:28:31,227 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) && ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0))) && ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) [2022-11-03 03:28:31,229 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == methaneLevelCritical))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)))) && ((((pumpRunning == 0 && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) [2022-11-03 03:28:31,229 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0)) && (((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(methAndRunningLastTime == 0)) [2022-11-03 03:28:31,231 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || tmp == 0) || !(0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0)) || (((1 <= pumpRunning && !(waterLevel == 1)) && tmp == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel)))) && (((((pumpRunning == \old(pumpRunning) && tmp == 0) && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel)))) && ((((pumpRunning == 0 && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) [2022-11-03 03:28:31,231 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || (pumpRunning == \old(pumpRunning) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) || !(methaneLevelCritical == 1)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) [2022-11-03 03:28:31,231 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || ((1 <= pumpRunning && !(waterLevel == 1)) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && 1 == systemActive)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && 1 == systemActive))) && (((((pumpRunning == 0 && methAndRunningLastTime == 0) && tmp == 1) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((((pumpRunning == \old(pumpRunning) && methAndRunningLastTime == 0) && tmp == 0) && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0)) || (((1 <= pumpRunning && methAndRunningLastTime == 0) && tmp == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) [2022-11-03 03:28:31,233 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) [2022-11-03 03:28:31,233 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (tmp <= 0 && 0 < tmp + 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0)) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (pumpRunning == 0 && (!(waterLevel == 1) || (tmp <= 0 && 0 < tmp + 1)))) || !(methAndRunningLastTime == 0)) [2022-11-03 03:28:31,285 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 03:28:31,286 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 03:28:31,287 INFO L158 Benchmark]: Toolchain (without parser) took 48083.40ms. Allocated memory was 102.8MB in the beginning and 388.0MB in the end (delta: 285.2MB). Free memory was 63.2MB in the beginning and 321.1MB in the end (delta: -257.9MB). Peak memory consumption was 27.1MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,287 INFO L158 Benchmark]: CDTParser took 0.39ms. Allocated memory is still 102.8MB. Free memory is still 80.4MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:28:31,288 INFO L158 Benchmark]: CACSL2BoogieTranslator took 693.43ms. Allocated memory is still 102.8MB. Free memory was 63.1MB in the beginning and 69.5MB in the end (delta: -6.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,288 INFO L158 Benchmark]: Boogie Procedure Inliner took 99.50ms. Allocated memory is still 102.8MB. Free memory was 69.5MB in the beginning and 67.1MB in the end (delta: 2.4MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,289 INFO L158 Benchmark]: Boogie Preprocessor took 64.39ms. Allocated memory is still 102.8MB. Free memory was 66.8MB in the beginning and 65.3MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:28:31,290 INFO L158 Benchmark]: RCFGBuilder took 878.61ms. Allocated memory was 102.8MB in the beginning and 123.7MB in the end (delta: 21.0MB). Free memory was 65.3MB in the beginning and 96.8MB in the end (delta: -31.6MB). Peak memory consumption was 32.2MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,290 INFO L158 Benchmark]: TraceAbstraction took 46207.40ms. Allocated memory was 123.7MB in the beginning and 388.0MB in the end (delta: 264.2MB). Free memory was 96.2MB in the beginning and 326.3MB in the end (delta: -230.1MB). Peak memory consumption was 234.5MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,290 INFO L158 Benchmark]: Witness Printer took 131.31ms. Allocated memory is still 388.0MB. Free memory was 326.3MB in the beginning and 321.1MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 03:28:31,294 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.39ms. Allocated memory is still 102.8MB. Free memory is still 80.4MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 693.43ms. Allocated memory is still 102.8MB. Free memory was 63.1MB in the beginning and 69.5MB in the end (delta: -6.4MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 99.50ms. Allocated memory is still 102.8MB. Free memory was 69.5MB in the beginning and 67.1MB in the end (delta: 2.4MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 64.39ms. Allocated memory is still 102.8MB. Free memory was 66.8MB in the beginning and 65.3MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 878.61ms. Allocated memory was 102.8MB in the beginning and 123.7MB in the end (delta: 21.0MB). Free memory was 65.3MB in the beginning and 96.8MB in the end (delta: -31.6MB). Peak memory consumption was 32.2MB. Max. memory is 16.1GB. * TraceAbstraction took 46207.40ms. Allocated memory was 123.7MB in the beginning and 388.0MB in the end (delta: 264.2MB). Free memory was 96.2MB in the beginning and 326.3MB in the end (delta: -230.1MB). Peak memory consumption was 234.5MB. Max. memory is 16.1GB. * Witness Printer took 131.31ms. Allocated memory is still 388.0MB. Free memory was 326.3MB in the beginning and 321.1MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 839]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 46.1s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 5.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 9.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1379 SdHoareTripleChecker+Valid, 2.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1349 mSDsluCounter, 2551 SdHoareTripleChecker+Invalid, 2.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2060 mSDsCounter, 525 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2628 IncrementalHoareTripleChecker+Invalid, 3153 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 525 mSolverCounterUnsat, 895 mSDtfsCounter, 2628 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 482 GetRequests, 328 SyntacticMatches, 15 SemanticMatches, 139 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2064 ImplicationChecksByTransitivity, 15.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=622occurred in iteration=11, InterpolantAutomatonStates: 101, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.7s AutomataMinimizationTime, 12 MinimizatonAttempts, 419 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 1694 PreInvPairs, 1894 NumberOfFragments, 3232 HoareAnnotationTreeSize, 1694 FomulaSimplifications, 5465 FormulaSimplificationTreeSizeReduction, 1.1s HoareSimplificationTime, 38 FomulaSimplificationsInter, 35305 FormulaSimplificationTreeSizeReductionInter, 8.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 3.4s InterpolantComputationTime, 744 NumberOfCodeBlocks, 744 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 798 ConstructedInterpolants, 0 QuantifiedInterpolants, 2045 SizeOfPredicates, 13 NumberOfNonLiveVariables, 1334 ConjunctsInSsa, 53 ConjunctsInUnsatCore, 16 InterpolantComputations, 11 PerfectInterpolantSequences, 241/284 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 206]: Loop Invariant Derived loop invariant: (((((((1 <= pumpRunning && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive)) || (((1 <= pumpRunning && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 1) && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: 205]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 196]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 845]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 271]: Loop Invariant Derived loop invariant: (((((((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) && ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 0))) && ((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((((((1 <= pumpRunning && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 307]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0)) && (((pumpRunning == \old(pumpRunning) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(methAndRunningLastTime == 0)) - InvariantResult [Line: 329]: Loop Invariant Derived loop invariant: (((((((((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && tmp == methaneLevelCritical))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)))) && ((((pumpRunning == 0 && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 236]: Loop Invariant Derived loop invariant: (((((((1 <= pumpRunning && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive)) || (((1 <= pumpRunning && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0)) || ((((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 1) && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: 449]: Loop Invariant Derived loop invariant: (methaneLevelCritical == 0 && (((pumpRunning == 0 && splverifierCounter == 0) && !(0 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && splverifierCounter == 0))) || (methaneLevelCritical == 1 && (((pumpRunning == 0 && splverifierCounter == 0) && !(0 == systemActive)) || ((pumpRunning == 0 && methAndRunningLastTime == 0) && splverifierCounter == 0))) - InvariantResult [Line: 839]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 930]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methAndRunningLastTime == 0) && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 70]: Loop Invariant Derived loop invariant: (((((((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || tmp == 0) || !(0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0)) || (((1 <= pumpRunning && !(waterLevel == 1)) && tmp == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel)))) && (((((pumpRunning == \old(pumpRunning) && tmp == 0) && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || methAndRunningLastTime == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1))) || (((1 <= pumpRunning && !(waterLevel == 1)) && methAndRunningLastTime == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel)))) && ((((pumpRunning == 0 && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 855]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: ((((((((!(\old(pumpRunning) == 0) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(0 == systemActive)) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || ((1 <= pumpRunning && !(waterLevel == 1)) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && 1 == systemActive)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && 1 == systemActive))) && (((((pumpRunning == 0 && methAndRunningLastTime == 0) && tmp == 1) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((((pumpRunning == \old(pumpRunning) && methAndRunningLastTime == 0) && tmp == 0) && tmp == methaneLevelCritical) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && (((((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((pumpRunning == 0 && methAndRunningLastTime == 0) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && tmp == 0)) || (((1 <= pumpRunning && methAndRunningLastTime == 0) && tmp == 0) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) - InvariantResult [Line: 930]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 311]: Loop Invariant Derived loop invariant: (((((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (tmp <= 0 && 0 < tmp + 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0)) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(methAndRunningLastTime == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (pumpRunning == 0 && (!(waterLevel == 1) || (tmp <= 0 && 0 < tmp + 1)))) || !(methAndRunningLastTime == 0)) - InvariantResult [Line: 375]: Loop Invariant Derived loop invariant: (((((((((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || (pumpRunning == \old(pumpRunning) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) || !(methaneLevelCritical == 1)) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(0 == systemActive))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 1))) && ((((!(\old(methAndRunningLastTime) == 0) || methAndRunningLastTime == 0) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || !(\old(methAndRunningLastTime) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || (pumpRunning == \old(pumpRunning) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) RESULT: Ultimate proved your program to be correct! [2022-11-03 03:28:31,404 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_0b406c50-5ef9-4a44-9bbe-0e6ab35604b2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE