./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash df3faf2d1bbcaed92e1c2eddcb5ae1d2459730e99808e363d537a0bc5d54e347 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 01:38:56,374 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 01:38:56,376 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 01:38:56,418 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 01:38:56,419 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 01:38:56,423 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 01:38:56,426 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 01:38:56,431 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 01:38:56,433 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 01:38:56,437 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 01:38:56,438 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 01:38:56,441 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 01:38:56,441 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 01:38:56,449 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 01:38:56,450 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 01:38:56,453 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 01:38:56,454 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 01:38:56,456 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 01:38:56,457 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 01:38:56,459 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 01:38:56,463 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 01:38:56,465 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 01:38:56,468 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 01:38:56,470 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 01:38:56,475 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 01:38:56,478 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 01:38:56,479 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 01:38:56,481 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 01:38:56,481 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 01:38:56,482 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 01:38:56,483 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 01:38:56,484 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 01:38:56,486 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 01:38:56,488 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 01:38:56,489 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 01:38:56,489 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 01:38:56,490 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 01:38:56,490 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 01:38:56,490 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 01:38:56,491 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 01:38:56,492 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 01:38:56,493 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 01:38:56,536 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 01:38:56,536 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 01:38:56,537 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 01:38:56,537 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 01:38:56,538 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 01:38:56,538 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 01:38:56,539 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 01:38:56,539 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 01:38:56,539 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 01:38:56,539 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 01:38:56,540 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 01:38:56,541 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 01:38:56,541 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 01:38:56,541 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 01:38:56,541 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 01:38:56,541 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 01:38:56,541 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 01:38:56,542 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 01:38:56,542 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 01:38:56,543 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 01:38:56,543 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 01:38:56,543 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 01:38:56,543 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 01:38:56,543 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 01:38:56,545 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 01:38:56,545 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 01:38:56,546 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 01:38:56,546 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 01:38:56,546 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 01:38:56,546 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 01:38:56,546 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 01:38:56,547 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 01:38:56,547 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 01:38:56,547 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 01:38:56,547 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 01:38:56,548 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 01:38:56,549 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> df3faf2d1bbcaed92e1c2eddcb5ae1d2459730e99808e363d537a0bc5d54e347 [2022-11-03 01:38:56,821 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 01:38:56,849 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 01:38:56,852 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 01:38:56,853 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 01:38:56,854 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 01:38:56,855 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c [2022-11-03 01:38:56,924 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/data/bacc66d4a/57992712ed3b42929f7891eab0e0d265/FLAGc5d550df0 [2022-11-03 01:38:57,461 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 01:38:57,461 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c [2022-11-03 01:38:57,473 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/data/bacc66d4a/57992712ed3b42929f7891eab0e0d265/FLAGc5d550df0 [2022-11-03 01:38:57,752 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/data/bacc66d4a/57992712ed3b42929f7891eab0e0d265 [2022-11-03 01:38:57,754 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 01:38:57,759 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 01:38:57,762 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 01:38:57,762 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 01:38:57,766 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 01:38:57,767 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 01:38:57" (1/1) ... [2022-11-03 01:38:57,770 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@13c2fb5b and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:57, skipping insertion in model container [2022-11-03 01:38:57,770 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 01:38:57" (1/1) ... [2022-11-03 01:38:57,778 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 01:38:57,833 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 01:38:58,051 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c[1605,1618] [2022-11-03 01:38:58,237 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 01:38:58,247 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 01:38:58,260 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/sv-benchmarks/c/product-lines/minepump_spec5_product39.cil.c[1605,1618] [2022-11-03 01:38:58,310 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 01:38:58,326 INFO L208 MainTranslator]: Completed translation [2022-11-03 01:38:58,327 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58 WrapperNode [2022-11-03 01:38:58,327 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 01:38:58,328 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 01:38:58,328 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 01:38:58,328 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 01:38:58,336 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,350 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,377 INFO L138 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 259 [2022-11-03 01:38:58,377 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 01:38:58,378 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 01:38:58,378 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 01:38:58,378 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 01:38:58,387 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,388 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,390 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,390 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,396 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,400 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,402 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,403 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,406 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 01:38:58,407 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 01:38:58,407 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 01:38:58,407 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 01:38:58,408 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (1/1) ... [2022-11-03 01:38:58,415 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 01:38:58,426 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 01:38:58,438 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 01:38:58,471 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 01:38:58,490 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 01:38:58,490 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 01:38:58,490 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 01:38:58,491 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 01:38:58,491 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 01:38:58,491 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 01:38:58,491 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 01:38:58,491 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 01:38:58,491 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 01:38:58,492 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 01:38:58,492 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 01:38:58,492 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-03 01:38:58,492 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-03 01:38:58,492 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-03 01:38:58,492 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-03 01:38:58,493 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 01:38:58,493 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 01:38:58,494 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 01:38:58,494 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 01:38:58,494 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 01:38:58,603 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 01:38:58,605 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 01:38:59,042 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 01:38:59,230 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 01:38:59,230 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 01:38:59,233 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 01:38:59 BoogieIcfgContainer [2022-11-03 01:38:59,233 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 01:38:59,235 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 01:38:59,235 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 01:38:59,239 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 01:38:59,240 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 01:38:57" (1/3) ... [2022-11-03 01:38:59,240 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1dad0154 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 01:38:59, skipping insertion in model container [2022-11-03 01:38:59,241 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 01:38:58" (2/3) ... [2022-11-03 01:38:59,241 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1dad0154 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 01:38:59, skipping insertion in model container [2022-11-03 01:38:59,241 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 01:38:59" (3/3) ... [2022-11-03 01:38:59,243 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product39.cil.c [2022-11-03 01:38:59,262 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 01:38:59,263 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 01:38:59,342 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 01:38:59,358 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@2d725900, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 01:38:59,358 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 01:38:59,363 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-03 01:38:59,376 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 01:38:59,376 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:38:59,377 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:38:59,378 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:38:59,385 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:38:59,386 INFO L85 PathProgramCache]: Analyzing trace with hash -1541196640, now seen corresponding path program 1 times [2022-11-03 01:38:59,396 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:38:59,396 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1760970288] [2022-11-03 01:38:59,397 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:38:59,397 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:38:59,581 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:38:59,658 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 01:38:59,659 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:38:59,660 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1760970288] [2022-11-03 01:38:59,660 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1760970288] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:38:59,661 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:38:59,661 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 01:38:59,662 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [841055855] [2022-11-03 01:38:59,663 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:38:59,668 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 01:38:59,668 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:38:59,695 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 01:38:59,696 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 01:38:59,699 INFO L87 Difference]: Start difference. First operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:38:59,812 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:38:59,813 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2022-11-03 01:38:59,814 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 01:38:59,816 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-03 01:38:59,816 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:38:59,828 INFO L225 Difference]: With dead ends: 130 [2022-11-03 01:38:59,828 INFO L226 Difference]: Without dead ends: 61 [2022-11-03 01:38:59,833 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 01:38:59,837 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 69 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 01:38:59,838 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 69 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 01:38:59,856 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-03 01:38:59,878 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-03 01:38:59,880 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 39 states have (on average 1.358974358974359) internal successors, (53), 47 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-03 01:38:59,888 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 80 transitions. [2022-11-03 01:38:59,890 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 80 transitions. Word has length 21 [2022-11-03 01:38:59,891 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:38:59,891 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 80 transitions. [2022-11-03 01:38:59,893 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:38:59,893 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 80 transitions. [2022-11-03 01:38:59,899 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-03 01:38:59,900 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:38:59,900 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:38:59,900 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 01:38:59,901 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:38:59,902 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:38:59,902 INFO L85 PathProgramCache]: Analyzing trace with hash 1038455851, now seen corresponding path program 1 times [2022-11-03 01:38:59,903 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:38:59,903 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [883264589] [2022-11-03 01:38:59,904 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:38:59,905 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:38:59,951 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:00,093 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 01:39:00,093 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:00,093 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [883264589] [2022-11-03 01:39:00,094 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [883264589] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:00,094 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:00,094 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 01:39:00,094 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1986530837] [2022-11-03 01:39:00,095 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:00,096 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 01:39:00,096 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:00,097 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 01:39:00,097 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 01:39:00,098 INFO L87 Difference]: Start difference. First operand 61 states and 80 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:39:00,145 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:00,145 INFO L93 Difference]: Finished difference Result 94 states and 122 transitions. [2022-11-03 01:39:00,146 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 01:39:00,146 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-03 01:39:00,146 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:00,147 INFO L225 Difference]: With dead ends: 94 [2022-11-03 01:39:00,147 INFO L226 Difference]: Without dead ends: 53 [2022-11-03 01:39:00,148 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 01:39:00,149 INFO L413 NwaCegarLoop]: 55 mSDtfsCounter, 14 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 93 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:00,150 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 93 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 01:39:00,151 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-03 01:39:00,157 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-03 01:39:00,158 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3823529411764706) internal successors, (47), 42 states have internal predecessors, (47), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-03 01:39:00,159 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 69 transitions. [2022-11-03 01:39:00,159 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 69 transitions. Word has length 22 [2022-11-03 01:39:00,160 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:00,160 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 69 transitions. [2022-11-03 01:39:00,160 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:39:00,160 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 69 transitions. [2022-11-03 01:39:00,161 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-03 01:39:00,162 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:00,162 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:00,162 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 01:39:00,162 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:00,163 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:00,163 INFO L85 PathProgramCache]: Analyzing trace with hash -2135358164, now seen corresponding path program 1 times [2022-11-03 01:39:00,163 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:00,164 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [106612064] [2022-11-03 01:39:00,164 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:00,164 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:00,186 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:00,288 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 01:39:00,288 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:00,288 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [106612064] [2022-11-03 01:39:00,289 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [106612064] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:00,289 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:00,289 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 01:39:00,289 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [167780836] [2022-11-03 01:39:00,290 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:00,290 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 01:39:00,290 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:00,291 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 01:39:00,291 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 01:39:00,292 INFO L87 Difference]: Start difference. First operand 53 states and 69 transitions. Second operand has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 01:39:00,364 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:00,364 INFO L93 Difference]: Finished difference Result 155 states and 204 transitions. [2022-11-03 01:39:00,368 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 01:39:00,369 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2022-11-03 01:39:00,369 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:00,371 INFO L225 Difference]: With dead ends: 155 [2022-11-03 01:39:00,371 INFO L226 Difference]: Without dead ends: 104 [2022-11-03 01:39:00,372 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 01:39:00,374 INFO L413 NwaCegarLoop]: 74 mSDtfsCounter, 54 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 54 SdHoareTripleChecker+Valid, 127 SdHoareTripleChecker+Invalid, 31 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:00,378 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [54 Valid, 127 Invalid, 31 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 01:39:00,379 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 104 states. [2022-11-03 01:39:00,394 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 104 to 101. [2022-11-03 01:39:00,401 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 101 states, 64 states have (on average 1.390625) internal successors, (89), 79 states have internal predecessors, (89), 22 states have call successors, (22), 14 states have call predecessors, (22), 14 states have return successors, (22), 15 states have call predecessors, (22), 22 states have call successors, (22) [2022-11-03 01:39:00,410 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 101 states to 101 states and 133 transitions. [2022-11-03 01:39:00,410 INFO L78 Accepts]: Start accepts. Automaton has 101 states and 133 transitions. Word has length 25 [2022-11-03 01:39:00,411 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:00,412 INFO L495 AbstractCegarLoop]: Abstraction has 101 states and 133 transitions. [2022-11-03 01:39:00,412 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 01:39:00,413 INFO L276 IsEmpty]: Start isEmpty. Operand 101 states and 133 transitions. [2022-11-03 01:39:00,416 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-03 01:39:00,419 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:00,420 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:00,420 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 01:39:00,420 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:00,421 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:00,421 INFO L85 PathProgramCache]: Analyzing trace with hash -1526516562, now seen corresponding path program 1 times [2022-11-03 01:39:00,422 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:00,423 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1898572225] [2022-11-03 01:39:00,425 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:00,425 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:00,459 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:00,636 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 01:39:00,636 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:00,636 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1898572225] [2022-11-03 01:39:00,637 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1898572225] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:00,637 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:00,637 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 01:39:00,637 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [509126486] [2022-11-03 01:39:00,638 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:00,639 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 01:39:00,640 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:00,641 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 01:39:00,641 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 01:39:00,641 INFO L87 Difference]: Start difference. First operand 101 states and 133 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:39:00,897 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:00,897 INFO L93 Difference]: Finished difference Result 282 states and 381 transitions. [2022-11-03 01:39:00,897 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 01:39:00,898 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2022-11-03 01:39:00,898 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:00,900 INFO L225 Difference]: With dead ends: 282 [2022-11-03 01:39:00,900 INFO L226 Difference]: Without dead ends: 183 [2022-11-03 01:39:00,901 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 01:39:00,903 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 34 mSDsluCounter, 254 mSDsCounter, 0 mSdLazyCounter, 117 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 284 SdHoareTripleChecker+Invalid, 126 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 117 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:00,903 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [35 Valid, 284 Invalid, 126 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 117 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 01:39:00,904 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 183 states. [2022-11-03 01:39:00,930 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 183 to 174. [2022-11-03 01:39:00,931 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 174 states, 115 states have (on average 1.3130434782608695) internal successors, (151), 130 states have internal predecessors, (151), 32 states have call successors, (32), 26 states have call predecessors, (32), 26 states have return successors, (40), 29 states have call predecessors, (40), 32 states have call successors, (40) [2022-11-03 01:39:00,932 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 174 states to 174 states and 223 transitions. [2022-11-03 01:39:00,932 INFO L78 Accepts]: Start accepts. Automaton has 174 states and 223 transitions. Word has length 28 [2022-11-03 01:39:00,933 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:00,933 INFO L495 AbstractCegarLoop]: Abstraction has 174 states and 223 transitions. [2022-11-03 01:39:00,933 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 01:39:00,933 INFO L276 IsEmpty]: Start isEmpty. Operand 174 states and 223 transitions. [2022-11-03 01:39:00,934 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-03 01:39:00,934 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:00,935 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:00,935 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 01:39:00,935 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:00,936 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:00,936 INFO L85 PathProgramCache]: Analyzing trace with hash 958213121, now seen corresponding path program 1 times [2022-11-03 01:39:00,936 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:00,936 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1554452835] [2022-11-03 01:39:00,937 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:00,937 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:00,956 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:01,345 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 01:39:01,348 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:01,348 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1554452835] [2022-11-03 01:39:01,348 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1554452835] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:01,349 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:01,349 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 01:39:01,350 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2033735268] [2022-11-03 01:39:01,350 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:01,351 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 01:39:01,351 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:01,351 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 01:39:01,352 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-03 01:39:01,352 INFO L87 Difference]: Start difference. First operand 174 states and 223 transitions. Second operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 01:39:01,540 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:01,540 INFO L93 Difference]: Finished difference Result 503 states and 647 transitions. [2022-11-03 01:39:01,541 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-03 01:39:01,541 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 33 [2022-11-03 01:39:01,541 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:01,544 INFO L225 Difference]: With dead ends: 503 [2022-11-03 01:39:01,544 INFO L226 Difference]: Without dead ends: 331 [2022-11-03 01:39:01,546 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-03 01:39:01,547 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 115 mSDsluCounter, 182 mSDsCounter, 0 mSdLazyCounter, 127 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 116 SdHoareTripleChecker+Valid, 247 SdHoareTripleChecker+Invalid, 147 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 127 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:01,548 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [116 Valid, 247 Invalid, 147 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 127 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 01:39:01,549 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 331 states. [2022-11-03 01:39:01,623 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 331 to 318. [2022-11-03 01:39:01,624 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 318 states, 212 states have (on average 1.2924528301886793) internal successors, (274), 235 states have internal predecessors, (274), 57 states have call successors, (57), 47 states have call predecessors, (57), 48 states have return successors, (74), 52 states have call predecessors, (74), 57 states have call successors, (74) [2022-11-03 01:39:01,626 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 318 states to 318 states and 405 transitions. [2022-11-03 01:39:01,627 INFO L78 Accepts]: Start accepts. Automaton has 318 states and 405 transitions. Word has length 33 [2022-11-03 01:39:01,627 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:01,627 INFO L495 AbstractCegarLoop]: Abstraction has 318 states and 405 transitions. [2022-11-03 01:39:01,628 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 01:39:01,628 INFO L276 IsEmpty]: Start isEmpty. Operand 318 states and 405 transitions. [2022-11-03 01:39:01,632 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-03 01:39:01,632 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:01,633 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:01,633 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 01:39:01,633 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:01,633 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:01,634 INFO L85 PathProgramCache]: Analyzing trace with hash -1510406170, now seen corresponding path program 1 times [2022-11-03 01:39:01,634 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:01,634 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2124962018] [2022-11-03 01:39:01,634 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:01,634 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:01,655 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:01,984 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 01:39:01,985 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:01,985 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2124962018] [2022-11-03 01:39:01,985 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2124962018] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:01,985 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:01,985 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 01:39:01,986 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1805809021] [2022-11-03 01:39:01,986 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:01,986 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 01:39:01,987 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:01,987 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 01:39:01,988 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=40, Unknown=0, NotChecked=0, Total=56 [2022-11-03 01:39:01,988 INFO L87 Difference]: Start difference. First operand 318 states and 405 transitions. Second operand has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 01:39:02,512 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:02,512 INFO L93 Difference]: Finished difference Result 798 states and 1039 transitions. [2022-11-03 01:39:02,513 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 01:39:02,513 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 36 [2022-11-03 01:39:02,513 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:02,518 INFO L225 Difference]: With dead ends: 798 [2022-11-03 01:39:02,518 INFO L226 Difference]: Without dead ends: 556 [2022-11-03 01:39:02,520 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 5 SyntacticMatches, 1 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 26 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=61, Invalid=149, Unknown=0, NotChecked=0, Total=210 [2022-11-03 01:39:02,521 INFO L413 NwaCegarLoop]: 81 mSDtfsCounter, 218 mSDsluCounter, 216 mSDsCounter, 0 mSdLazyCounter, 309 mSolverCounterSat, 104 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 228 SdHoareTripleChecker+Valid, 269 SdHoareTripleChecker+Invalid, 413 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 104 IncrementalHoareTripleChecker+Valid, 309 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:02,522 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [228 Valid, 269 Invalid, 413 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [104 Valid, 309 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-03 01:39:02,523 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 556 states. [2022-11-03 01:39:02,593 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 556 to 514. [2022-11-03 01:39:02,594 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 514 states, 346 states have (on average 1.2919075144508672) internal successors, (447), 384 states have internal predecessors, (447), 90 states have call successors, (90), 68 states have call predecessors, (90), 77 states have return successors, (121), 87 states have call predecessors, (121), 90 states have call successors, (121) [2022-11-03 01:39:02,598 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 514 states to 514 states and 658 transitions. [2022-11-03 01:39:02,598 INFO L78 Accepts]: Start accepts. Automaton has 514 states and 658 transitions. Word has length 36 [2022-11-03 01:39:02,598 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:02,598 INFO L495 AbstractCegarLoop]: Abstraction has 514 states and 658 transitions. [2022-11-03 01:39:02,599 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 01:39:02,599 INFO L276 IsEmpty]: Start isEmpty. Operand 514 states and 658 transitions. [2022-11-03 01:39:02,601 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 58 [2022-11-03 01:39:02,601 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:02,601 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:02,601 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 01:39:02,602 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:02,602 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:02,602 INFO L85 PathProgramCache]: Analyzing trace with hash 1071944550, now seen corresponding path program 1 times [2022-11-03 01:39:02,602 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:02,602 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [983696913] [2022-11-03 01:39:02,602 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:02,603 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:02,618 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:02,652 INFO L134 CoverageAnalysis]: Checked inductivity of 20 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 01:39:02,652 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:02,653 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [983696913] [2022-11-03 01:39:02,653 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [983696913] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:02,653 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 01:39:02,653 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 01:39:02,653 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1757918778] [2022-11-03 01:39:02,653 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:02,654 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 01:39:02,654 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:02,654 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 01:39:02,654 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 01:39:02,654 INFO L87 Difference]: Start difference. First operand 514 states and 658 transitions. Second operand has 4 states, 3 states have (on average 14.0) internal successors, (42), 4 states have internal predecessors, (42), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) [2022-11-03 01:39:02,786 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:02,786 INFO L93 Difference]: Finished difference Result 620 states and 792 transitions. [2022-11-03 01:39:02,787 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 01:39:02,787 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 14.0) internal successors, (42), 4 states have internal predecessors, (42), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) Word has length 57 [2022-11-03 01:39:02,787 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:02,789 INFO L225 Difference]: With dead ends: 620 [2022-11-03 01:39:02,789 INFO L226 Difference]: Without dead ends: 247 [2022-11-03 01:39:02,790 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 01:39:02,791 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 94 mSDsluCounter, 67 mSDsCounter, 0 mSdLazyCounter, 80 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 94 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 82 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 80 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:02,792 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [94 Valid, 128 Invalid, 82 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 80 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 01:39:02,792 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 247 states. [2022-11-03 01:39:02,843 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 247 to 247. [2022-11-03 01:39:02,844 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 247 states, 167 states have (on average 1.2395209580838322) internal successors, (207), 184 states have internal predecessors, (207), 42 states have call successors, (42), 32 states have call predecessors, (42), 37 states have return successors, (57), 42 states have call predecessors, (57), 42 states have call successors, (57) [2022-11-03 01:39:02,846 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 247 states to 247 states and 306 transitions. [2022-11-03 01:39:02,846 INFO L78 Accepts]: Start accepts. Automaton has 247 states and 306 transitions. Word has length 57 [2022-11-03 01:39:02,846 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:02,846 INFO L495 AbstractCegarLoop]: Abstraction has 247 states and 306 transitions. [2022-11-03 01:39:02,847 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 14.0) internal successors, (42), 4 states have internal predecessors, (42), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) [2022-11-03 01:39:02,847 INFO L276 IsEmpty]: Start isEmpty. Operand 247 states and 306 transitions. [2022-11-03 01:39:02,848 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2022-11-03 01:39:02,848 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:02,848 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:02,848 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-03 01:39:02,848 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:02,849 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:02,849 INFO L85 PathProgramCache]: Analyzing trace with hash -1124819293, now seen corresponding path program 1 times [2022-11-03 01:39:02,849 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:02,849 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [20740847] [2022-11-03 01:39:02,849 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:02,849 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:02,866 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:02,964 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 8 proven. 11 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-03 01:39:02,965 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:02,965 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [20740847] [2022-11-03 01:39:02,965 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [20740847] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 01:39:02,965 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1787899673] [2022-11-03 01:39:02,965 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:02,965 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:02,965 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 01:39:02,975 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 01:39:02,981 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 01:39:03,109 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:03,112 INFO L263 TraceCheckSpWp]: Trace formula consists of 440 conjuncts, 4 conjunts are in the unsatisfiable core [2022-11-03 01:39:03,122 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 01:39:03,221 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 01:39:03,222 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-03 01:39:03,222 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1787899673] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 01:39:03,222 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-03 01:39:03,222 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [7] total 8 [2022-11-03 01:39:03,222 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1196372820] [2022-11-03 01:39:03,223 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 01:39:03,223 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 01:39:03,223 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:03,223 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 01:39:03,224 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2022-11-03 01:39:03,224 INFO L87 Difference]: Start difference. First operand 247 states and 306 transitions. Second operand has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 01:39:03,307 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:03,308 INFO L93 Difference]: Finished difference Result 369 states and 461 transitions. [2022-11-03 01:39:03,308 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 01:39:03,308 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 62 [2022-11-03 01:39:03,309 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:03,310 INFO L225 Difference]: With dead ends: 369 [2022-11-03 01:39:03,310 INFO L226 Difference]: Without dead ends: 237 [2022-11-03 01:39:03,311 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 69 GetRequests, 63 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2022-11-03 01:39:03,311 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 30 mSDsluCounter, 43 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 30 SdHoareTripleChecker+Valid, 113 SdHoareTripleChecker+Invalid, 32 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:03,312 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [30 Valid, 113 Invalid, 32 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 01:39:03,312 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2022-11-03 01:39:03,336 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 237. [2022-11-03 01:39:03,337 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 237 states, 160 states have (on average 1.2125) internal successors, (194), 176 states have internal predecessors, (194), 40 states have call successors, (40), 32 states have call predecessors, (40), 36 states have return successors, (47), 40 states have call predecessors, (47), 40 states have call successors, (47) [2022-11-03 01:39:03,339 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 237 states to 237 states and 281 transitions. [2022-11-03 01:39:03,339 INFO L78 Accepts]: Start accepts. Automaton has 237 states and 281 transitions. Word has length 62 [2022-11-03 01:39:03,339 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:03,339 INFO L495 AbstractCegarLoop]: Abstraction has 237 states and 281 transitions. [2022-11-03 01:39:03,340 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 01:39:03,340 INFO L276 IsEmpty]: Start isEmpty. Operand 237 states and 281 transitions. [2022-11-03 01:39:03,341 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-03 01:39:03,341 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:03,341 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:03,382 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-03 01:39:03,561 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:03,561 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:03,562 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:03,562 INFO L85 PathProgramCache]: Analyzing trace with hash -1077474185, now seen corresponding path program 1 times [2022-11-03 01:39:03,562 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:03,562 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1203689483] [2022-11-03 01:39:03,562 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:03,562 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:03,596 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:03,803 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 5 proven. 15 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 01:39:03,803 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:03,803 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1203689483] [2022-11-03 01:39:03,803 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1203689483] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 01:39:03,803 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2109509765] [2022-11-03 01:39:03,803 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:03,804 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:03,804 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 01:39:03,808 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 01:39:03,831 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 01:39:03,932 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:03,934 INFO L263 TraceCheckSpWp]: Trace formula consists of 442 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-03 01:39:03,940 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 01:39:04,098 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 19 proven. 7 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 01:39:04,098 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 01:39:04,309 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 01:39:04,309 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2109509765] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 01:39:04,309 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [678600321] [2022-11-03 01:39:04,329 INFO L159 IcfgInterpreter]: Started Sifa with 42 locations of interest [2022-11-03 01:39:04,329 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 01:39:04,332 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 01:39:04,337 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 01:39:04,338 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 01:39:11,822 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 306 for LOIs [2022-11-03 01:39:11,898 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 29 for LOIs [2022-11-03 01:39:12,248 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2022-11-03 01:39:12,261 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 64 for LOIs [2022-11-03 01:39:12,552 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 40 for LOIs [2022-11-03 01:39:12,556 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 01:39:25,936 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '7809#(and (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 0)) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (= |timeShift_getWaterLevel_~retValue_acc~10#1| ~waterLevel~0) (<= |old(~pumpRunning~0)| 2147483647) (= 1 ~systemActive~0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| 2)) (<= ~methaneLevelCritical~0 0) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (<= 0 ~head~0.base) (<= 0 ~methaneLevelCritical~0) (<= 0 (+ |timeShift_getWaterLevel_~retValue_acc~10#1| 2147483648)) (<= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| |timeShift_getWaterLevel_#res#1|) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 2147483648)) (<= |timeShift_getWaterLevel_~retValue_acc~10#1| 2147483647) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~10#1| |timeShift_getWaterLevel_#res#1|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 01:39:25,936 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 01:39:25,936 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 01:39:25,936 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 6, 6] total 15 [2022-11-03 01:39:25,937 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1772133242] [2022-11-03 01:39:25,937 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 01:39:25,937 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2022-11-03 01:39:25,938 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:25,938 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2022-11-03 01:39:25,939 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=278, Invalid=1884, Unknown=0, NotChecked=0, Total=2162 [2022-11-03 01:39:25,939 INFO L87 Difference]: Start difference. First operand 237 states and 281 transitions. Second operand has 15 states, 12 states have (on average 7.333333333333333) internal successors, (88), 13 states have internal predecessors, (88), 7 states have call successors, (20), 4 states have call predecessors, (20), 8 states have return successors, (18), 9 states have call predecessors, (18), 7 states have call successors, (18) [2022-11-03 01:39:26,723 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:26,723 INFO L93 Difference]: Finished difference Result 308 states and 374 transitions. [2022-11-03 01:39:26,724 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-03 01:39:26,724 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 12 states have (on average 7.333333333333333) internal successors, (88), 13 states have internal predecessors, (88), 7 states have call successors, (20), 4 states have call predecessors, (20), 8 states have return successors, (18), 9 states have call predecessors, (18), 7 states have call successors, (18) Word has length 65 [2022-11-03 01:39:26,724 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:26,726 INFO L225 Difference]: With dead ends: 308 [2022-11-03 01:39:26,726 INFO L226 Difference]: Without dead ends: 306 [2022-11-03 01:39:26,728 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 223 GetRequests, 159 SyntacticMatches, 5 SemanticMatches, 59 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1237 ImplicationChecksByTransitivity, 13.9s TimeCoverageRelationStatistics Valid=450, Invalid=3210, Unknown=0, NotChecked=0, Total=3660 [2022-11-03 01:39:26,729 INFO L413 NwaCegarLoop]: 123 mSDtfsCounter, 200 mSDsluCounter, 513 mSDsCounter, 0 mSdLazyCounter, 325 mSolverCounterSat, 127 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 202 SdHoareTripleChecker+Valid, 544 SdHoareTripleChecker+Invalid, 452 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 127 IncrementalHoareTripleChecker+Valid, 325 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:26,729 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [202 Valid, 544 Invalid, 452 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [127 Valid, 325 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 01:39:26,730 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2022-11-03 01:39:26,754 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 285. [2022-11-03 01:39:26,754 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 191 states have (on average 1.2041884816753927) internal successors, (230), 212 states have internal predecessors, (230), 49 states have call successors, (49), 40 states have call predecessors, (49), 44 states have return successors, (60), 48 states have call predecessors, (60), 49 states have call successors, (60) [2022-11-03 01:39:26,756 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 339 transitions. [2022-11-03 01:39:26,756 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 339 transitions. Word has length 65 [2022-11-03 01:39:26,757 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:26,757 INFO L495 AbstractCegarLoop]: Abstraction has 285 states and 339 transitions. [2022-11-03 01:39:26,757 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 15 states, 12 states have (on average 7.333333333333333) internal successors, (88), 13 states have internal predecessors, (88), 7 states have call successors, (20), 4 states have call predecessors, (20), 8 states have return successors, (18), 9 states have call predecessors, (18), 7 states have call successors, (18) [2022-11-03 01:39:26,757 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 339 transitions. [2022-11-03 01:39:26,759 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 87 [2022-11-03 01:39:26,759 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:26,759 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:26,803 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-03 01:39:26,971 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2022-11-03 01:39:26,971 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:26,972 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:26,972 INFO L85 PathProgramCache]: Analyzing trace with hash -731455868, now seen corresponding path program 1 times [2022-11-03 01:39:26,972 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:26,972 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [363526016] [2022-11-03 01:39:26,973 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:26,973 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:26,991 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:27,206 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 35 proven. 3 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-11-03 01:39:27,207 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:27,207 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [363526016] [2022-11-03 01:39:27,207 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [363526016] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 01:39:27,207 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1892065996] [2022-11-03 01:39:27,207 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:27,208 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:27,209 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 01:39:27,210 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 01:39:27,235 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 01:39:27,331 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:27,334 INFO L263 TraceCheckSpWp]: Trace formula consists of 525 conjuncts, 18 conjunts are in the unsatisfiable core [2022-11-03 01:39:27,337 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 01:39:27,544 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 61 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-03 01:39:27,544 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 01:39:27,873 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 48 proven. 3 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-03 01:39:27,873 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1892065996] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 01:39:27,873 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [121690824] [2022-11-03 01:39:27,875 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-03 01:39:27,876 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 01:39:27,876 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 01:39:27,876 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 01:39:27,876 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 01:39:34,322 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 308 for LOIs [2022-11-03 01:39:34,390 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-03 01:39:34,712 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 56 for LOIs [2022-11-03 01:39:34,720 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-03 01:39:34,738 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 01:39:47,311 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '9297#(and (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (= |timeShift_getWaterLevel_~retValue_acc~10#1| ~waterLevel~0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| 2)) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (= |old(~waterLevel~0)| ~waterLevel~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| |timeShift_getWaterLevel_#res#1|) (<= |timeShift_getWaterLevel_~retValue_acc~10#1| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~10#1| |timeShift_getWaterLevel_#res#1|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= 2 |timeShift_getWaterLevel_~retValue_acc~10#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 01:39:47,311 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 01:39:47,311 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 01:39:47,311 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 9] total 20 [2022-11-03 01:39:47,311 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1339101859] [2022-11-03 01:39:47,311 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 01:39:47,312 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-03 01:39:47,312 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:39:47,313 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-03 01:39:47,314 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=280, Invalid=1976, Unknown=0, NotChecked=0, Total=2256 [2022-11-03 01:39:47,314 INFO L87 Difference]: Start difference. First operand 285 states and 339 transitions. Second operand has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-03 01:39:49,044 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:39:49,044 INFO L93 Difference]: Finished difference Result 848 states and 1107 transitions. [2022-11-03 01:39:49,045 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-03 01:39:49,045 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) Word has length 86 [2022-11-03 01:39:49,046 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:39:49,048 INFO L225 Difference]: With dead ends: 848 [2022-11-03 01:39:49,048 INFO L226 Difference]: Without dead ends: 557 [2022-11-03 01:39:49,051 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 311 GetRequests, 233 SyntacticMatches, 5 SemanticMatches, 73 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2046 ImplicationChecksByTransitivity, 13.5s TimeCoverageRelationStatistics Valid=656, Invalid=4894, Unknown=0, NotChecked=0, Total=5550 [2022-11-03 01:39:49,052 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 489 mSDsluCounter, 616 mSDsCounter, 0 mSdLazyCounter, 1184 mSolverCounterSat, 277 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 492 SdHoareTripleChecker+Valid, 628 SdHoareTripleChecker+Invalid, 1461 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 277 IncrementalHoareTripleChecker+Valid, 1184 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2022-11-03 01:39:49,053 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [492 Valid, 628 Invalid, 1461 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [277 Valid, 1184 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2022-11-03 01:39:49,054 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 557 states. [2022-11-03 01:39:49,102 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 557 to 346. [2022-11-03 01:39:49,103 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 346 states, 233 states have (on average 1.167381974248927) internal successors, (272), 255 states have internal predecessors, (272), 56 states have call successors, (56), 50 states have call predecessors, (56), 56 states have return successors, (71), 57 states have call predecessors, (71), 56 states have call successors, (71) [2022-11-03 01:39:49,105 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 346 states to 346 states and 399 transitions. [2022-11-03 01:39:49,106 INFO L78 Accepts]: Start accepts. Automaton has 346 states and 399 transitions. Word has length 86 [2022-11-03 01:39:49,106 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:39:49,106 INFO L495 AbstractCegarLoop]: Abstraction has 346 states and 399 transitions. [2022-11-03 01:39:49,107 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-03 01:39:49,107 INFO L276 IsEmpty]: Start isEmpty. Operand 346 states and 399 transitions. [2022-11-03 01:39:49,108 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2022-11-03 01:39:49,108 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 01:39:49,108 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:39:49,142 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 01:39:49,327 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:49,328 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 01:39:49,328 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 01:39:49,328 INFO L85 PathProgramCache]: Analyzing trace with hash -1080808183, now seen corresponding path program 1 times [2022-11-03 01:39:49,328 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 01:39:49,328 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1876872267] [2022-11-03 01:39:49,328 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:49,329 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 01:39:49,358 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:50,414 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 15 proven. 42 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 01:39:50,414 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 01:39:50,414 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1876872267] [2022-11-03 01:39:50,414 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1876872267] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 01:39:50,414 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1256010048] [2022-11-03 01:39:50,414 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 01:39:50,415 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 01:39:50,415 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 01:39:50,416 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 01:39:50,441 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-03 01:39:50,532 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 01:39:50,535 INFO L263 TraceCheckSpWp]: Trace formula consists of 539 conjuncts, 30 conjunts are in the unsatisfiable core [2022-11-03 01:39:50,538 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 01:39:50,910 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 57 proven. 16 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 01:39:50,910 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 01:39:51,444 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 52 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 01:39:51,444 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1256010048] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 01:39:51,444 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1915721992] [2022-11-03 01:39:51,447 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-03 01:39:51,447 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 01:39:51,448 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 01:39:51,448 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 01:39:51,448 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 01:39:56,239 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 55 for LOIs [2022-11-03 01:39:56,250 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-03 01:39:56,579 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 56 for LOIs [2022-11-03 01:39:56,592 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-03 01:39:56,613 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 01:40:02,840 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '11758#(and (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (= |timeShift_getWaterLevel_~retValue_acc~10#1| ~waterLevel~0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| 2)) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (= |old(~waterLevel~0)| ~waterLevel~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| |timeShift_getWaterLevel_#res#1|) (<= |timeShift_getWaterLevel_~retValue_acc~10#1| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~10#1| |timeShift_getWaterLevel_#res#1|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= 2 |timeShift_getWaterLevel_~retValue_acc~10#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 01:40:02,841 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 01:40:02,841 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 01:40:02,841 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [20, 11, 11] total 34 [2022-11-03 01:40:02,841 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1819387308] [2022-11-03 01:40:02,842 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 01:40:02,842 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 34 states [2022-11-03 01:40:02,842 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 01:40:02,843 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 34 interpolants. [2022-11-03 01:40:02,844 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=449, Invalid=3333, Unknown=0, NotChecked=0, Total=3782 [2022-11-03 01:40:02,844 INFO L87 Difference]: Start difference. First operand 346 states and 399 transitions. Second operand has 34 states, 33 states have (on average 4.515151515151516) internal successors, (149), 34 states have internal predecessors, (149), 18 states have call successors, (30), 8 states have call predecessors, (30), 12 states have return successors, (28), 18 states have call predecessors, (28), 17 states have call successors, (28) [2022-11-03 01:40:06,830 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 01:40:06,830 INFO L93 Difference]: Finished difference Result 857 states and 1019 transitions. [2022-11-03 01:40:06,831 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 56 states. [2022-11-03 01:40:06,831 INFO L78 Accepts]: Start accepts. Automaton has has 34 states, 33 states have (on average 4.515151515151516) internal successors, (149), 34 states have internal predecessors, (149), 18 states have call successors, (30), 8 states have call predecessors, (30), 12 states have return successors, (28), 18 states have call predecessors, (28), 17 states have call successors, (28) Word has length 91 [2022-11-03 01:40:06,831 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 01:40:06,832 INFO L225 Difference]: With dead ends: 857 [2022-11-03 01:40:06,832 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 01:40:06,837 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 381 GetRequests, 258 SyntacticMatches, 9 SemanticMatches, 114 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4916 ImplicationChecksByTransitivity, 8.9s TimeCoverageRelationStatistics Valid=1702, Invalid=11638, Unknown=0, NotChecked=0, Total=13340 [2022-11-03 01:40:06,837 INFO L413 NwaCegarLoop]: 142 mSDtfsCounter, 2095 mSDsluCounter, 990 mSDsCounter, 0 mSdLazyCounter, 1841 mSolverCounterSat, 1481 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 2095 SdHoareTripleChecker+Valid, 1009 SdHoareTripleChecker+Invalid, 3322 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1481 IncrementalHoareTripleChecker+Valid, 1841 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.7s IncrementalHoareTripleChecker+Time [2022-11-03 01:40:06,838 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [2095 Valid, 1009 Invalid, 3322 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1481 Valid, 1841 Invalid, 0 Unknown, 0 Unchecked, 1.7s Time] [2022-11-03 01:40:06,838 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 01:40:06,838 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 01:40:06,839 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 01:40:06,839 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 01:40:06,839 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2022-11-03 01:40:06,839 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 01:40:06,839 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 01:40:06,840 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 34 states, 33 states have (on average 4.515151515151516) internal successors, (149), 34 states have internal predecessors, (149), 18 states have call successors, (30), 8 states have call predecessors, (30), 12 states have return successors, (28), 18 states have call predecessors, (28), 17 states have call successors, (28) [2022-11-03 01:40:06,840 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 01:40:06,840 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 01:40:06,843 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 01:40:06,870 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Ended with exit code 0 [2022-11-03 01:40:07,057 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-03 01:40:07,059 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 01:40:13,570 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 206 213) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 01:40:13,570 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 206 213) no Hoare annotation was computed. [2022-11-03 01:40:13,570 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 139 145) no Hoare annotation was computed. [2022-11-03 01:40:13,570 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 139 145) the Hoare annotation is: true [2022-11-03 01:40:13,570 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 915 926) the Hoare annotation is: true [2022-11-03 01:40:13,570 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 915 926) no Hoare annotation was computed. [2022-11-03 01:40:13,571 INFO L899 garLoopResultBuilder]: For program point L320(lines 320 324) no Hoare annotation was computed. [2022-11-03 01:40:13,571 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 306 335) no Hoare annotation was computed. [2022-11-03 01:40:13,571 INFO L902 garLoopResultBuilder]: At program point L320-1(lines 320 324) the Hoare annotation is: true [2022-11-03 01:40:13,571 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 306 335) the Hoare annotation is: true [2022-11-03 01:40:13,571 INFO L902 garLoopResultBuilder]: At program point L316-2(lines 316 330) the Hoare annotation is: true [2022-11-03 01:40:13,571 INFO L902 garLoopResultBuilder]: At program point L312(line 312) the Hoare annotation is: true [2022-11-03 01:40:13,572 INFO L899 garLoopResultBuilder]: For program point L312-1(line 312) no Hoare annotation was computed. [2022-11-03 01:40:13,572 INFO L902 garLoopResultBuilder]: At program point L331(lines 306 335) the Hoare annotation is: true [2022-11-03 01:40:13,572 INFO L899 garLoopResultBuilder]: For program point L327(line 327) no Hoare annotation was computed. [2022-11-03 01:40:13,572 INFO L895 garLoopResultBuilder]: At program point L192(line 192) the Hoare annotation is: (let ((.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse4 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0 .cse2) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3))) (or (not (<= |old(~waterLevel~0)| 1)) .cse3 .cse4 .cse0) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-03 01:40:13,573 INFO L895 garLoopResultBuilder]: At program point L192-1(lines 173 197) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse12 (and .cse6 .cse9)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= ~pumpRunning~0 1)) (.cse11 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse2 (= ~waterLevel~0 1))) (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (and .cse6 .cse2 .cse3))) (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (let ((.cse8 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse10))) (or .cse7 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or .cse8 .cse9) .cse3 .cse4) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse6 (or (and (not .cse10) .cse9) .cse8) .cse3)))) (or .cse7 .cse11 .cse12 .cse0) (or .cse11 .cse12 .cse0 .cse5 (and .cse9 .cse4)) (or .cse11 (not (= 0 ~systemActive~0)))))) [2022-11-03 01:40:13,573 INFO L895 garLoopResultBuilder]: At program point L126-1(lines 126 132) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse8 (not (= 0 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse10 (not (<= |old(~waterLevel~0)| 1))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse13 (and .cse6 .cse9)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= ~pumpRunning~0 1))) (and (let ((.cse2 (= ~waterLevel~0 1))) (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (and .cse6 .cse2 .cse3))) (or .cse7 .cse6 .cse8) (or .cse7 (not (< 1 |old(~waterLevel~0)|)) .cse9 (not (<= |old(~waterLevel~0)| 2)) .cse8) (or .cse10 .cse7 (not (<= 1 |old(~waterLevel~0)|)) .cse9 .cse8) (let ((.cse12 (< 0 |old(~waterLevel~0)|))) (let ((.cse11 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse12))) (or .cse10 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or .cse11 .cse9) .cse3 .cse4) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse6 (or (and (not .cse12) .cse9) .cse11) .cse3)))) (or .cse10 .cse7 .cse13 .cse0) (or .cse7 .cse13 .cse0 .cse5 (and .cse9 .cse4))))) [2022-11-03 01:40:13,573 INFO L899 garLoopResultBuilder]: For program point L506(lines 506 512) no Hoare annotation was computed. [2022-11-03 01:40:13,574 INFO L895 garLoopResultBuilder]: At program point L503(line 503) the Hoare annotation is: (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 0 ~systemActive~0))) (.cse6 (not (= 1 ~systemActive~0))) (.cse8 (= ~pumpRunning~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| ~waterLevel~0)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse9 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse3 .cse2) (or (and .cse1 .cse4 .cse3 .cse5) .cse6 .cse7 (and .cse4 .cse3 .cse5 .cse8) (not (<= |old(~waterLevel~0)| 0)) .cse9) (or .cse0 .cse6 (and .cse1 (<= ~waterLevel~0 1) .cse4 .cse3) (not (< |old(~waterLevel~0)| 3))) (let ((.cse10 (= ~waterLevel~0 1))) (or .cse6 .cse7 (and .cse4 .cse10 .cse5 .cse8) (not (= |old(~waterLevel~0)| 2)) (and .cse1 .cse4 .cse10 .cse5))) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2)) .cse2) (let ((.cse11 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse12 (< 0 |old(~waterLevel~0)|))) (or (not (= |old(~waterLevel~0)| 1)) .cse6 (and .cse11 .cse12 .cse4 .cse5 .cse8) .cse7 (and .cse1 .cse11 .cse12 .cse4 .cse5) .cse9)))) [2022-11-03 01:40:13,574 INFO L899 garLoopResultBuilder]: For program point L503-1(line 503) no Hoare annotation was computed. [2022-11-03 01:40:13,574 INFO L899 garLoopResultBuilder]: For program point L119-2(lines 115 137) no Hoare annotation was computed. [2022-11-03 01:40:13,574 INFO L899 garLoopResultBuilder]: For program point L181(lines 181 189) no Hoare annotation was computed. [2022-11-03 01:40:13,575 INFO L895 garLoopResultBuilder]: At program point L177(lines 177 194) the Hoare annotation is: (let ((.cse8 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse6 (and (= ~pumpRunning~0 0) .cse8)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) .cse4) (or .cse5 .cse6 .cse0 .cse4) (or .cse7 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) .cse8) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse7 .cse5 .cse6 .cse0) (or .cse5 (not (= 0 ~systemActive~0)))))) [2022-11-03 01:40:13,575 INFO L895 garLoopResultBuilder]: At program point L54(line 54) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (< |old(~waterLevel~0)| 3))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2))) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2) (or .cse3 .cse0 .cse2) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-03 01:40:13,575 INFO L895 garLoopResultBuilder]: At program point L488(line 488) the Hoare annotation is: (let ((.cse10 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse3 (and .cse10 (= ~pumpRunning~0 1))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (and (= ~pumpRunning~0 0) .cse10)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 (not (= 0 ~systemActive~0))) (or .cse1 .cse2 .cse7 .cse4 .cse8) (or .cse5 .cse6 .cse1 .cse9) (or .cse5 .cse1 .cse7 .cse4 .cse8) (or .cse1 .cse2 .cse9 .cse3) (or .cse0 .cse5 .cse6 .cse1)))) [2022-11-03 01:40:13,575 INFO L895 garLoopResultBuilder]: At program point L488-1(line 488) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse8 (= 1 ~systemActive~0)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (and .cse4 .cse8 .cse5)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~waterLevel~0)| 2))) (.cse2 (not .cse8)) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (and .cse5 (<= 1 |timeShift___utac_acc__Specification5_spec__2_#t~ret22#1|) (= ~pumpRunning~0 1)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 .cse3) (or .cse1 (and .cse4 .cse5) (not (= 0 ~systemActive~0))) (or .cse2 .cse6 .cse3 .cse7) (or .cse2 .cse6 .cse7 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3)))))) [2022-11-03 01:40:13,576 INFO L895 garLoopResultBuilder]: At program point L187(line 187) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse4 (not (= 0 ~systemActive~0))))) [2022-11-03 01:40:13,576 INFO L899 garLoopResultBuilder]: For program point L505(lines 505 515) no Hoare annotation was computed. [2022-11-03 01:40:13,576 INFO L895 garLoopResultBuilder]: At program point L183(line 183) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse4 (not (= 0 ~systemActive~0))))) [2022-11-03 01:40:13,576 INFO L899 garLoopResultBuilder]: For program point L501(lines 501 518) no Hoare annotation was computed. [2022-11-03 01:40:13,577 INFO L895 garLoopResultBuilder]: At program point L501-1(lines 493 521) the Hoare annotation is: (let ((.cse8 (= 1 ~systemActive~0))) (let ((.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse13 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| 2)) (.cse10 (not (= 0 ~systemActive~0))) (.cse9 (not (= |old(~pumpRunning~0)| 0))) (.cse11 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (not .cse8)) (.cse5 (= ~pumpRunning~0 1)) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (= ~pumpRunning~0 0)) (.cse2 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~5#1| ~waterLevel~0)) (.cse12 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (<= 1 ~switchedOnBeforeTS~0))) (and (let ((.cse3 (= ~waterLevel~0 1))) (or .cse0 .cse1 (and .cse2 .cse3 .cse4 .cse5) .cse6 (and .cse7 .cse8 .cse2 .cse3 .cse4))) (or .cse9 .cse7 .cse10) (or .cse11 .cse9 (not (<= 1 |old(~waterLevel~0)|)) .cse12 .cse10) (or (and .cse12 .cse13 .cse5) .cse9 .cse0 (and .cse7 .cse8 .cse12 .cse13) .cse6) (or .cse9 (and .cse12 .cse13) (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2)) .cse10) (or .cse11 .cse9 .cse0 (and .cse7 .cse8 .cse2 .cse12)) (let ((.cse15 (< 0 |old(~waterLevel~0)|))) (let ((.cse14 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse15))) (or .cse11 .cse0 (and .cse2 (<= ~waterLevel~0 0) (or .cse14 .cse12) .cse4 .cse5) .cse1 (and .cse7 .cse8 .cse2 (or (and (not .cse15) .cse12) .cse14) .cse4) (not (<= 1 |old(~switchedOnBeforeTS~0)|)))))))) [2022-11-03 01:40:13,577 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 112 138) the Hoare annotation is: (let ((.cse10 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse3 (and .cse10 (= ~pumpRunning~0 1))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (and (= ~pumpRunning~0 0) .cse10)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 (not (= 0 ~systemActive~0))) (or .cse1 .cse2 .cse7 .cse4 .cse8) (or .cse5 .cse6 .cse1 .cse9) (or .cse5 .cse1 .cse7 .cse4 .cse8) (or .cse1 .cse2 .cse9 .cse3) (or .cse0 .cse5 .cse6 .cse1)))) [2022-11-03 01:40:13,577 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 112 138) no Hoare annotation was computed. [2022-11-03 01:40:13,577 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-03 01:40:13,578 INFO L899 garLoopResultBuilder]: For program point L436(lines 436 442) no Hoare annotation was computed. [2022-11-03 01:40:13,578 INFO L899 garLoopResultBuilder]: For program point L436-1(lines 436 442) no Hoare annotation was computed. [2022-11-03 01:40:13,578 INFO L895 garLoopResultBuilder]: At program point L461(lines 416 463) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (= 2 ~waterLevel~0) .cse1 .cse2 .cse4))) [2022-11-03 01:40:13,578 INFO L895 garLoopResultBuilder]: At program point L428(line 428) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (= 2 ~waterLevel~0) .cse1 .cse2 .cse4))) [2022-11-03 01:40:13,578 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 01:40:13,579 INFO L895 garLoopResultBuilder]: At program point L392(lines 392 399) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-03 01:40:13,579 INFO L902 garLoopResultBuilder]: At program point L392-2(lines 392 399) the Hoare annotation is: true [2022-11-03 01:40:13,579 INFO L899 garLoopResultBuilder]: For program point L293(lines 293 299) no Hoare annotation was computed. [2022-11-03 01:40:13,579 INFO L895 garLoopResultBuilder]: At program point L293-1(lines 293 299) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-03 01:40:13,579 INFO L899 garLoopResultBuilder]: For program point L417(lines 416 463) no Hoare annotation was computed. [2022-11-03 01:40:13,579 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 01:40:13,579 INFO L899 garLoopResultBuilder]: For program point L446(lines 446 459) no Hoare annotation was computed. [2022-11-03 01:40:13,580 INFO L895 garLoopResultBuilder]: At program point L438(line 438) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (= 2 ~waterLevel~0) .cse1 .cse2 .cse4))) [2022-11-03 01:40:13,580 INFO L902 garLoopResultBuilder]: At program point L467(lines 406 471) the Hoare annotation is: true [2022-11-03 01:40:13,580 INFO L899 garLoopResultBuilder]: For program point L426(lines 426 432) no Hoare annotation was computed. [2022-11-03 01:40:13,580 INFO L899 garLoopResultBuilder]: For program point L426-1(lines 426 432) no Hoare annotation was computed. [2022-11-03 01:40:13,580 INFO L895 garLoopResultBuilder]: At program point L464(lines 415 465) the Hoare annotation is: false [2022-11-03 01:40:13,580 INFO L895 garLoopResultBuilder]: At program point L295(line 295) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 1 ~systemActive~0) .cse0) (and (<= 2 ~waterLevel~0) .cse0 (not (= 0 ~systemActive~0))))) [2022-11-03 01:40:13,581 INFO L899 garLoopResultBuilder]: For program point L452(lines 452 458) no Hoare annotation was computed. [2022-11-03 01:40:13,581 INFO L895 garLoopResultBuilder]: At program point L452-2(lines 446 459) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (= 2 ~waterLevel~0) .cse1 .cse2 .cse4))) [2022-11-03 01:40:13,581 INFO L895 garLoopResultBuilder]: At program point L161(line 161) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 .cse3) (or (not (<= ~waterLevel~0 0)) .cse1 .cse2 .cse3) (or .cse0 .cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (not (<= ~waterLevel~0 1))))) [2022-11-03 01:40:13,581 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 147 171) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 01:40:13,582 INFO L895 garLoopResultBuilder]: At program point L155(lines 155 163) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 .cse3) (or (not (<= ~waterLevel~0 0)) .cse1 .cse2 .cse3) (or .cse0 .cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (not (<= ~waterLevel~0 1))))) [2022-11-03 01:40:13,582 INFO L895 garLoopResultBuilder]: At program point L151(lines 151 168) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 01:40:13,582 INFO L895 garLoopResultBuilder]: At program point L166(line 166) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 01:40:13,582 INFO L899 garLoopResultBuilder]: For program point L166-1(lines 147 171) no Hoare annotation was computed. [2022-11-03 01:40:13,582 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 147 171) no Hoare annotation was computed. [2022-11-03 01:40:13,583 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 903 914) no Hoare annotation was computed. [2022-11-03 01:40:13,583 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 903 914) the Hoare annotation is: (let ((.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~pumpRunning~0 1))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 (not (= 0 ~systemActive~0))) (or .cse2 .cse3 .cse4 .cse1) (or .cse0 .cse2 .cse4 .cse1) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse2 .cse1) (or .cse2 .cse3 .cse1 (not (<= 1 ~switchedOnBeforeTS~0)) (not (< |old(~waterLevel~0)| 3))))) [2022-11-03 01:40:13,583 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 225 233) no Hoare annotation was computed. [2022-11-03 01:40:13,583 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 225 233) the Hoare annotation is: true [2022-11-03 01:40:13,587 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 01:40:13,589 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 01:40:13,620 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 01:40:13 BoogieIcfgContainer [2022-11-03 01:40:13,620 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 01:40:13,620 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 01:40:13,620 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 01:40:13,621 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 01:40:13,621 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 01:38:59" (3/4) ... [2022-11-03 01:40:13,624 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 01:40:13,632 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-03 01:40:13,632 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 01:40:13,632 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 01:40:13,633 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 01:40:13,633 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 01:40:13,633 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 01:40:13,633 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 01:40:13,633 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-03 01:40:13,640 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 74 nodes and edges [2022-11-03 01:40:13,641 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 26 nodes and edges [2022-11-03 01:40:13,641 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 14 nodes and edges [2022-11-03 01:40:13,642 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 01:40:13,642 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 01:40:13,643 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 01:40:13,643 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 01:40:13,667 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(waterLevel) <= 1) || ((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) [2022-11-03 01:40:13,668 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(0 == systemActive))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) [2022-11-03 01:40:13,668 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || (((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(0 == systemActive))) && ((((((\old(waterLevel) == waterLevel && tmp == 2) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == 2)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || (\old(waterLevel) == waterLevel && tmp == 2)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || ((((tmp == waterLevel && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(switchedOnBeforeTS))) [2022-11-03 01:40:13,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 01:40:13,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 01:40:13,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 01:40:13,669 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2022-11-03 01:40:13,671 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || tmp == 0) || !(waterLevel <= 1)) [2022-11-03 01:40:13,696 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 01:40:13,696 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 01:40:13,697 INFO L158 Benchmark]: Toolchain (without parser) took 75938.11ms. Allocated memory was 98.6MB in the beginning and 545.3MB in the end (delta: 446.7MB). Free memory was 58.6MB in the beginning and 438.4MB in the end (delta: -379.7MB). Peak memory consumption was 67.8MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,697 INFO L158 Benchmark]: CDTParser took 0.32ms. Allocated memory is still 98.6MB. Free memory is still 75.9MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 01:40:13,697 INFO L158 Benchmark]: CACSL2BoogieTranslator took 565.64ms. Allocated memory is still 98.6MB. Free memory was 58.5MB in the beginning and 66.9MB in the end (delta: -8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,698 INFO L158 Benchmark]: Boogie Procedure Inliner took 49.39ms. Allocated memory is still 98.6MB. Free memory was 66.9MB in the beginning and 64.0MB in the end (delta: 2.9MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,698 INFO L158 Benchmark]: Boogie Preprocessor took 28.18ms. Allocated memory is still 98.6MB. Free memory was 64.0MB in the beginning and 62.3MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,699 INFO L158 Benchmark]: RCFGBuilder took 826.44ms. Allocated memory is still 98.6MB. Free memory was 62.3MB in the beginning and 70.3MB in the end (delta: -8.0MB). Peak memory consumption was 30.1MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,699 INFO L158 Benchmark]: TraceAbstraction took 74384.75ms. Allocated memory was 98.6MB in the beginning and 545.3MB in the end (delta: 446.7MB). Free memory was 69.3MB in the beginning and 444.7MB in the end (delta: -375.4MB). Peak memory consumption was 331.4MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,699 INFO L158 Benchmark]: Witness Printer took 75.70ms. Allocated memory is still 545.3MB. Free memory was 444.7MB in the beginning and 438.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-03 01:40:13,701 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.32ms. Allocated memory is still 98.6MB. Free memory is still 75.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 565.64ms. Allocated memory is still 98.6MB. Free memory was 58.5MB in the beginning and 66.9MB in the end (delta: -8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 49.39ms. Allocated memory is still 98.6MB. Free memory was 66.9MB in the beginning and 64.0MB in the end (delta: 2.9MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 28.18ms. Allocated memory is still 98.6MB. Free memory was 64.0MB in the beginning and 62.3MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 826.44ms. Allocated memory is still 98.6MB. Free memory was 62.3MB in the beginning and 70.3MB in the end (delta: -8.0MB). Peak memory consumption was 30.1MB. Max. memory is 16.1GB. * TraceAbstraction took 74384.75ms. Allocated memory was 98.6MB in the beginning and 545.3MB in the end (delta: 446.7MB). Free memory was 69.3MB in the beginning and 444.7MB in the end (delta: -375.4MB). Peak memory consumption was 331.4MB. Max. memory is 16.1GB. * Witness Printer took 75.70ms. Allocated memory is still 545.3MB. Free memory was 444.7MB in the beginning and 438.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 74.3s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 8.1s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 6.5s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3364 SdHoareTripleChecker+Valid, 3.8s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3343 mSDsluCounter, 3511 SdHoareTripleChecker+Invalid, 3.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2994 mSDsCounter, 2022 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4087 IncrementalHoareTripleChecker+Invalid, 6109 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 2022 mSolverCounterUnsat, 944 mSDtfsCounter, 4087 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1034 GetRequests, 733 SyntacticMatches, 20 SemanticMatches, 281 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8238 ImplicationChecksByTransitivity, 36.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=514occurred in iteration=6, InterpolantAutomatonStates: 149, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 299 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 1359 PreInvPairs, 1577 NumberOfFragments, 2296 HoareAnnotationTreeSize, 1359 FomulaSimplifications, 6314 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 38 FomulaSimplificationsInter, 23439 FormulaSimplificationTreeSizeReductionInter, 5.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 4.7s InterpolantComputationTime, 830 NumberOfCodeBlocks, 830 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1054 ConstructedInterpolants, 0 QuantifiedInterpolants, 3201 SizeOfPredicates, 26 NumberOfNonLiveVariables, 1946 ConjunctsInSsa, 60 ConjunctsInUnsatCore, 18 InterpolantComputations, 8 PerfectInterpolantSequences, 496/607 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 177]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 416]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel < 3) || ((((1 == systemActive && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && pumpRunning == 1)) || ((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive)) || (((2 == waterLevel && 1 == systemActive) && splverifierCounter == 0) && pumpRunning == 1) - InvariantResult [Line: 293]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 493]: Loop Invariant Derived loop invariant: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || (((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(0 == systemActive))) && ((((((\old(waterLevel) == waterLevel && tmp == 2) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) && tmp == 2)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || (\old(waterLevel) == waterLevel && tmp == 2)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && \old(waterLevel) == waterLevel))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || ((((tmp == waterLevel && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS)) || !(1 <= \old(switchedOnBeforeTS))) - InvariantResult [Line: 415]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 488]: Loop Invariant Derived loop invariant: ((((((!(\old(waterLevel) <= 1) || ((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) && (((((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) - InvariantResult [Line: 406]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 126]: Loop Invariant Derived loop invariant: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(0 == systemActive))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) - InvariantResult [Line: 173]: Loop Invariant Derived loop invariant: (((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 306]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 155]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || tmp == 0) || !(waterLevel <= 1)) RESULT: Ultimate proved your program to be correct! [2022-11-03 01:40:13,768 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ac067c34-81ad-463d-ab73-b641e2286b25/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE