./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash e5a4c274bc0fec0eeea8ea2f72c4bc5bbc7aef2fd24f2cf907e22c2c7f3759d4 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 02:03:56,953 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 02:03:56,956 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 02:03:57,010 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 02:03:57,010 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 02:03:57,016 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 02:03:57,019 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 02:03:57,025 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 02:03:57,028 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 02:03:57,035 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 02:03:57,036 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 02:03:57,040 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 02:03:57,040 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 02:03:57,044 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 02:03:57,046 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 02:03:57,049 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 02:03:57,051 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 02:03:57,052 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 02:03:57,055 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 02:03:57,067 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 02:03:57,069 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 02:03:57,071 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 02:03:57,075 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 02:03:57,076 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 02:03:57,087 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 02:03:57,088 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 02:03:57,089 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 02:03:57,091 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 02:03:57,092 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 02:03:57,095 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 02:03:57,096 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 02:03:57,097 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 02:03:57,099 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 02:03:57,100 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 02:03:57,101 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 02:03:57,101 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 02:03:57,102 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 02:03:57,102 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 02:03:57,102 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 02:03:57,103 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 02:03:57,104 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 02:03:57,109 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 02:03:57,167 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 02:03:57,167 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 02:03:57,168 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 02:03:57,169 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 02:03:57,170 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 02:03:57,170 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 02:03:57,170 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 02:03:57,171 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 02:03:57,171 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 02:03:57,171 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 02:03:57,173 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 02:03:57,173 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 02:03:57,173 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 02:03:57,173 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 02:03:57,174 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 02:03:57,174 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 02:03:57,174 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 02:03:57,174 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 02:03:57,175 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 02:03:57,176 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 02:03:57,176 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 02:03:57,176 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 02:03:57,176 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 02:03:57,177 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 02:03:57,177 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 02:03:57,177 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 02:03:57,177 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 02:03:57,178 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 02:03:57,178 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 02:03:57,178 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 02:03:57,179 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 02:03:57,179 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 02:03:57,179 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 02:03:57,180 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 02:03:57,180 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 02:03:57,180 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 02:03:57,180 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 02:03:57,181 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 02:03:57,183 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 02:03:57,183 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 02:03:57,184 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 02:03:57,184 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> e5a4c274bc0fec0eeea8ea2f72c4bc5bbc7aef2fd24f2cf907e22c2c7f3759d4 [2022-11-03 02:03:57,600 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 02:03:57,636 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 02:03:57,639 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 02:03:57,641 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 02:03:57,644 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 02:03:57,646 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c [2022-11-03 02:03:57,730 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/data/afab1e643/24e249a057de4d599b07d3551536aace/FLAGf1e3ce684 [2022-11-03 02:03:58,481 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 02:03:58,482 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c [2022-11-03 02:03:58,506 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/data/afab1e643/24e249a057de4d599b07d3551536aace/FLAGf1e3ce684 [2022-11-03 02:03:58,724 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/data/afab1e643/24e249a057de4d599b07d3551536aace [2022-11-03 02:03:58,727 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 02:03:58,729 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 02:03:58,731 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 02:03:58,731 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 02:03:58,736 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 02:03:58,737 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 02:03:58" (1/1) ... [2022-11-03 02:03:58,738 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1ef437d9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:58, skipping insertion in model container [2022-11-03 02:03:58,739 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 02:03:58" (1/1) ... [2022-11-03 02:03:58,748 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 02:03:58,791 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 02:03:59,182 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c[18537,18550] [2022-11-03 02:03:59,186 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 02:03:59,198 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 02:03:59,292 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/sv-benchmarks/c/product-lines/minepump_spec5_product43.cil.c[18537,18550] [2022-11-03 02:03:59,296 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 02:03:59,328 INFO L208 MainTranslator]: Completed translation [2022-11-03 02:03:59,329 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59 WrapperNode [2022-11-03 02:03:59,329 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 02:03:59,331 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 02:03:59,331 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 02:03:59,331 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 02:03:59,341 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,377 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,414 INFO L138 Inliner]: procedures = 56, calls = 156, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 258 [2022-11-03 02:03:59,415 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 02:03:59,416 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 02:03:59,416 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 02:03:59,416 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 02:03:59,428 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,428 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,431 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,432 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,437 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,443 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,446 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,447 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,450 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 02:03:59,451 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 02:03:59,452 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 02:03:59,452 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 02:03:59,453 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (1/1) ... [2022-11-03 02:03:59,462 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 02:03:59,492 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:03:59,515 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 02:03:59,524 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 02:03:59,571 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 02:03:59,571 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 02:03:59,571 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 02:03:59,572 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 02:03:59,572 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 02:03:59,572 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 02:03:59,572 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 02:03:59,572 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 02:03:59,573 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 02:03:59,573 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-03 02:03:59,573 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-03 02:03:59,573 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 02:03:59,573 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 02:03:59,573 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 02:03:59,574 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 02:03:59,574 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 02:03:59,725 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 02:03:59,727 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 02:04:00,280 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 02:04:00,498 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 02:04:00,498 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 02:04:00,505 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:04:00 BoogieIcfgContainer [2022-11-03 02:04:00,505 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 02:04:00,509 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 02:04:00,509 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 02:04:00,513 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 02:04:00,514 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 02:03:58" (1/3) ... [2022-11-03 02:04:00,514 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11a5d9ca and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 02:04:00, skipping insertion in model container [2022-11-03 02:04:00,515 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:03:59" (2/3) ... [2022-11-03 02:04:00,515 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11a5d9ca and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 02:04:00, skipping insertion in model container [2022-11-03 02:04:00,515 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:04:00" (3/3) ... [2022-11-03 02:04:00,518 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product43.cil.c [2022-11-03 02:04:00,542 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 02:04:00,543 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 02:04:00,649 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 02:04:00,670 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4795f165, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 02:04:00,675 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 02:04:00,683 INFO L276 IsEmpty]: Start isEmpty. Operand has 51 states, 33 states have (on average 1.4242424242424243) internal successors, (47), 39 states have internal predecessors, (47), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 9 states have call predecessors, (10), 10 states have call successors, (10) [2022-11-03 02:04:00,696 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 02:04:00,696 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:00,697 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:00,698 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:00,707 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:00,708 INFO L85 PathProgramCache]: Analyzing trace with hash 1388192853, now seen corresponding path program 1 times [2022-11-03 02:04:00,720 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:00,722 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [465648989] [2022-11-03 02:04:00,723 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:00,724 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:00,894 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:01,024 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:04:01,025 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:01,025 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [465648989] [2022-11-03 02:04:01,026 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [465648989] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:01,026 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:01,026 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 02:04:01,028 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [836200474] [2022-11-03 02:04:01,028 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:01,033 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 02:04:01,033 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:01,074 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 02:04:01,074 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 02:04:01,077 INFO L87 Difference]: Start difference. First operand has 51 states, 33 states have (on average 1.4242424242424243) internal successors, (47), 39 states have internal predecessors, (47), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 9 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:04:01,148 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:01,149 INFO L93 Difference]: Finished difference Result 100 states and 135 transitions. [2022-11-03 02:04:01,150 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 02:04:01,151 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-03 02:04:01,152 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:01,159 INFO L225 Difference]: With dead ends: 100 [2022-11-03 02:04:01,159 INFO L226 Difference]: Without dead ends: 46 [2022-11-03 02:04:01,163 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 02:04:01,166 INFO L413 NwaCegarLoop]: 49 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 15 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 49 SdHoareTripleChecker+Invalid, 16 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 15 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:01,168 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 49 Invalid, 16 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 15 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 02:04:01,185 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 46 states. [2022-11-03 02:04:01,204 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 46 to 46. [2022-11-03 02:04:01,206 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 46 states, 30 states have (on average 1.3) internal successors, (39), 35 states have internal predecessors, (39), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 8 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-03 02:04:01,208 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 46 states to 46 states and 58 transitions. [2022-11-03 02:04:01,209 INFO L78 Accepts]: Start accepts. Automaton has 46 states and 58 transitions. Word has length 21 [2022-11-03 02:04:01,223 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:01,224 INFO L495 AbstractCegarLoop]: Abstraction has 46 states and 58 transitions. [2022-11-03 02:04:01,225 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:04:01,225 INFO L276 IsEmpty]: Start isEmpty. Operand 46 states and 58 transitions. [2022-11-03 02:04:01,230 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-03 02:04:01,230 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:01,230 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:01,230 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 02:04:01,231 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:01,231 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:01,232 INFO L85 PathProgramCache]: Analyzing trace with hash -1382298679, now seen corresponding path program 1 times [2022-11-03 02:04:01,232 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:01,232 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1847967315] [2022-11-03 02:04:01,232 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:01,233 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:01,267 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:01,378 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:04:01,379 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:01,379 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1847967315] [2022-11-03 02:04:01,379 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1847967315] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:01,379 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:01,380 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 02:04:01,380 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [200736698] [2022-11-03 02:04:01,380 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:01,381 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 02:04:01,382 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:01,382 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 02:04:01,383 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:04:01,383 INFO L87 Difference]: Start difference. First operand 46 states and 58 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:04:01,465 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:01,465 INFO L93 Difference]: Finished difference Result 69 states and 87 transitions. [2022-11-03 02:04:01,468 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 02:04:01,468 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-03 02:04:01,468 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:01,471 INFO L225 Difference]: With dead ends: 69 [2022-11-03 02:04:01,471 INFO L226 Difference]: Without dead ends: 38 [2022-11-03 02:04:01,472 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:04:01,474 INFO L413 NwaCegarLoop]: 35 mSDtfsCounter, 7 mSDsluCounter, 35 mSDsCounter, 0 mSdLazyCounter, 21 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 61 SdHoareTripleChecker+Invalid, 21 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 21 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:01,474 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 61 Invalid, 21 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 21 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 02:04:01,475 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 38 states. [2022-11-03 02:04:01,486 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 38 to 38. [2022-11-03 02:04:01,487 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 38 states, 25 states have (on average 1.32) internal successors, (33), 30 states have internal predecessors, (33), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 6 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-03 02:04:01,491 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 38 states to 38 states and 47 transitions. [2022-11-03 02:04:01,492 INFO L78 Accepts]: Start accepts. Automaton has 38 states and 47 transitions. Word has length 22 [2022-11-03 02:04:01,492 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:01,493 INFO L495 AbstractCegarLoop]: Abstraction has 38 states and 47 transitions. [2022-11-03 02:04:01,494 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:04:01,495 INFO L276 IsEmpty]: Start isEmpty. Operand 38 states and 47 transitions. [2022-11-03 02:04:01,496 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-03 02:04:01,497 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:01,497 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:01,497 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 02:04:01,497 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:01,510 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:01,510 INFO L85 PathProgramCache]: Analyzing trace with hash 987876177, now seen corresponding path program 1 times [2022-11-03 02:04:01,510 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:01,510 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1093638937] [2022-11-03 02:04:01,511 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:01,511 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:01,561 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:01,807 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:04:01,808 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:01,808 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1093638937] [2022-11-03 02:04:01,809 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1093638937] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:01,810 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:01,810 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 02:04:01,811 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1039465790] [2022-11-03 02:04:01,811 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:01,812 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 02:04:01,813 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:01,814 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 02:04:01,814 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-11-03 02:04:01,814 INFO L87 Difference]: Start difference. First operand 38 states and 47 transitions. Second operand has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 02:04:02,244 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:02,244 INFO L93 Difference]: Finished difference Result 145 states and 181 transitions. [2022-11-03 02:04:02,245 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 02:04:02,245 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 24 [2022-11-03 02:04:02,245 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:02,247 INFO L225 Difference]: With dead ends: 145 [2022-11-03 02:04:02,247 INFO L226 Difference]: Without dead ends: 109 [2022-11-03 02:04:02,248 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=59, Invalid=213, Unknown=0, NotChecked=0, Total=272 [2022-11-03 02:04:02,249 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 74 mSDsluCounter, 300 mSDsCounter, 0 mSdLazyCounter, 339 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 76 SdHoareTripleChecker+Valid, 289 SdHoareTripleChecker+Invalid, 361 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 339 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:02,250 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [76 Valid, 289 Invalid, 361 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 339 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 02:04:02,251 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 109 states. [2022-11-03 02:04:02,265 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 109 to 76. [2022-11-03 02:04:02,266 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 50 states have (on average 1.26) internal successors, (63), 56 states have internal predecessors, (63), 13 states have call successors, (13), 12 states have call predecessors, (13), 12 states have return successors, (15), 12 states have call predecessors, (15), 13 states have call successors, (15) [2022-11-03 02:04:02,267 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 91 transitions. [2022-11-03 02:04:02,267 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 91 transitions. Word has length 24 [2022-11-03 02:04:02,268 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:02,268 INFO L495 AbstractCegarLoop]: Abstraction has 76 states and 91 transitions. [2022-11-03 02:04:02,268 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 02:04:02,269 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 91 transitions. [2022-11-03 02:04:02,269 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 28 [2022-11-03 02:04:02,270 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:02,270 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:02,270 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 02:04:02,270 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:02,271 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:02,271 INFO L85 PathProgramCache]: Analyzing trace with hash -2066109895, now seen corresponding path program 1 times [2022-11-03 02:04:02,271 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:02,272 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1458382782] [2022-11-03 02:04:02,272 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:02,272 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:02,313 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:02,839 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 02:04:02,839 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:02,841 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1458382782] [2022-11-03 02:04:02,842 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1458382782] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:02,842 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:02,842 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-11-03 02:04:02,842 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [324906047] [2022-11-03 02:04:02,843 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:02,844 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-03 02:04:02,844 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:02,845 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-03 02:04:02,845 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=56, Unknown=0, NotChecked=0, Total=72 [2022-11-03 02:04:02,845 INFO L87 Difference]: Start difference. First operand 76 states and 91 transitions. Second operand has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 02:04:03,347 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:03,347 INFO L93 Difference]: Finished difference Result 250 states and 317 transitions. [2022-11-03 02:04:03,348 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 20 states. [2022-11-03 02:04:03,348 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 27 [2022-11-03 02:04:03,348 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:03,354 INFO L225 Difference]: With dead ends: 250 [2022-11-03 02:04:03,354 INFO L226 Difference]: Without dead ends: 176 [2022-11-03 02:04:03,359 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 26 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 21 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 82 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=114, Invalid=392, Unknown=0, NotChecked=0, Total=506 [2022-11-03 02:04:03,361 INFO L413 NwaCegarLoop]: 58 mSDtfsCounter, 128 mSDsluCounter, 315 mSDsCounter, 0 mSdLazyCounter, 235 mSolverCounterSat, 62 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 131 SdHoareTripleChecker+Valid, 328 SdHoareTripleChecker+Invalid, 297 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 62 IncrementalHoareTripleChecker+Valid, 235 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:03,365 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [131 Valid, 328 Invalid, 297 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [62 Valid, 235 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 02:04:03,368 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 176 states. [2022-11-03 02:04:03,392 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 176 to 146. [2022-11-03 02:04:03,392 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 146 states, 97 states have (on average 1.2268041237113403) internal successors, (119), 108 states have internal predecessors, (119), 24 states have call successors, (24), 22 states have call predecessors, (24), 24 states have return successors, (33), 23 states have call predecessors, (33), 24 states have call successors, (33) [2022-11-03 02:04:03,394 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 146 states to 146 states and 176 transitions. [2022-11-03 02:04:03,394 INFO L78 Accepts]: Start accepts. Automaton has 146 states and 176 transitions. Word has length 27 [2022-11-03 02:04:03,395 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:03,395 INFO L495 AbstractCegarLoop]: Abstraction has 146 states and 176 transitions. [2022-11-03 02:04:03,395 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 02:04:03,395 INFO L276 IsEmpty]: Start isEmpty. Operand 146 states and 176 transitions. [2022-11-03 02:04:03,396 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-11-03 02:04:03,397 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:03,397 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:03,397 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 02:04:03,397 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:03,398 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:03,398 INFO L85 PathProgramCache]: Analyzing trace with hash -1419551120, now seen corresponding path program 1 times [2022-11-03 02:04:03,398 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:03,398 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1645444433] [2022-11-03 02:04:03,398 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:03,399 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:03,416 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:03,703 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:04:03,704 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:03,704 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1645444433] [2022-11-03 02:04:03,704 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1645444433] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:03,704 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:03,705 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 02:04:03,705 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1191082704] [2022-11-03 02:04:03,705 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:03,705 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 02:04:03,706 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:03,706 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 02:04:03,706 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=40, Unknown=0, NotChecked=0, Total=56 [2022-11-03 02:04:03,707 INFO L87 Difference]: Start difference. First operand 146 states and 176 transitions. Second operand has 8 states, 7 states have (on average 3.142857142857143) internal successors, (22), 7 states have internal predecessors, (22), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 02:04:04,194 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:04,194 INFO L93 Difference]: Finished difference Result 414 states and 509 transitions. [2022-11-03 02:04:04,195 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 02:04:04,196 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.142857142857143) internal successors, (22), 7 states have internal predecessors, (22), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 30 [2022-11-03 02:04:04,197 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:04,204 INFO L225 Difference]: With dead ends: 414 [2022-11-03 02:04:04,204 INFO L226 Difference]: Without dead ends: 301 [2022-11-03 02:04:04,211 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 32 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=68, Invalid=142, Unknown=0, NotChecked=0, Total=210 [2022-11-03 02:04:04,212 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 120 mSDsluCounter, 264 mSDsCounter, 0 mSdLazyCounter, 275 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 125 SdHoareTripleChecker+Valid, 278 SdHoareTripleChecker+Invalid, 320 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 275 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:04,212 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [125 Valid, 278 Invalid, 320 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 275 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 02:04:04,214 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 301 states. [2022-11-03 02:04:04,284 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 301 to 231. [2022-11-03 02:04:04,286 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 231 states, 155 states have (on average 1.2258064516129032) internal successors, (190), 172 states have internal predecessors, (190), 37 states have call successors, (37), 33 states have call predecessors, (37), 38 states have return successors, (51), 36 states have call predecessors, (51), 37 states have call successors, (51) [2022-11-03 02:04:04,295 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 231 states to 231 states and 278 transitions. [2022-11-03 02:04:04,295 INFO L78 Accepts]: Start accepts. Automaton has 231 states and 278 transitions. Word has length 30 [2022-11-03 02:04:04,296 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:04,296 INFO L495 AbstractCegarLoop]: Abstraction has 231 states and 278 transitions. [2022-11-03 02:04:04,296 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.142857142857143) internal successors, (22), 7 states have internal predecessors, (22), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 02:04:04,297 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 278 transitions. [2022-11-03 02:04:04,305 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-11-03 02:04:04,305 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:04,306 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:04,306 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 02:04:04,307 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:04,307 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:04,308 INFO L85 PathProgramCache]: Analyzing trace with hash -1598941202, now seen corresponding path program 1 times [2022-11-03 02:04:04,308 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:04,309 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1934134357] [2022-11-03 02:04:04,309 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:04,309 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:04,344 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:04,478 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 02:04:04,478 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:04,479 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1934134357] [2022-11-03 02:04:04,480 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1934134357] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:04,480 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:04,480 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 02:04:04,480 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1003129595] [2022-11-03 02:04:04,480 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:04,481 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 02:04:04,481 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:04,481 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 02:04:04,482 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:04:04,482 INFO L87 Difference]: Start difference. First operand 231 states and 278 transitions. Second operand has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 3 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2022-11-03 02:04:04,565 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:04,565 INFO L93 Difference]: Finished difference Result 464 states and 572 transitions. [2022-11-03 02:04:04,566 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 02:04:04,566 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 3 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) Word has length 47 [2022-11-03 02:04:04,567 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:04,569 INFO L225 Difference]: With dead ends: 464 [2022-11-03 02:04:04,569 INFO L226 Difference]: Without dead ends: 198 [2022-11-03 02:04:04,570 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:04:04,572 INFO L413 NwaCegarLoop]: 51 mSDtfsCounter, 17 mSDsluCounter, 43 mSDsCounter, 0 mSdLazyCounter, 32 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 17 SdHoareTripleChecker+Valid, 84 SdHoareTripleChecker+Invalid, 32 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 32 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:04,574 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [17 Valid, 84 Invalid, 32 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 32 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 02:04:04,576 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 198 states. [2022-11-03 02:04:04,627 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 198 to 198. [2022-11-03 02:04:04,628 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 198 states, 132 states have (on average 1.1818181818181819) internal successors, (156), 146 states have internal predecessors, (156), 33 states have call successors, (33), 30 states have call predecessors, (33), 32 states have return successors, (44), 32 states have call predecessors, (44), 33 states have call successors, (44) [2022-11-03 02:04:04,630 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 233 transitions. [2022-11-03 02:04:04,630 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 233 transitions. Word has length 47 [2022-11-03 02:04:04,632 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:04,632 INFO L495 AbstractCegarLoop]: Abstraction has 198 states and 233 transitions. [2022-11-03 02:04:04,633 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 11.333333333333334) internal successors, (34), 3 states have internal predecessors, (34), 3 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2022-11-03 02:04:04,633 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 233 transitions. [2022-11-03 02:04:04,638 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 54 [2022-11-03 02:04:04,638 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:04,638 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:04,638 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 02:04:04,639 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:04,641 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:04,641 INFO L85 PathProgramCache]: Analyzing trace with hash -1315798111, now seen corresponding path program 1 times [2022-11-03 02:04:04,641 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:04,641 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [976417766] [2022-11-03 02:04:04,642 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:04,642 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:04,675 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:04,940 INFO L134 CoverageAnalysis]: Checked inductivity of 22 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 02:04:04,941 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:04,941 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [976417766] [2022-11-03 02:04:04,941 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [976417766] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:04,941 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:04,942 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 02:04:04,942 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1503893021] [2022-11-03 02:04:04,942 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:04,942 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 02:04:04,943 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:04,943 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 02:04:04,943 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=32, Unknown=0, NotChecked=0, Total=56 [2022-11-03 02:04:04,944 INFO L87 Difference]: Start difference. First operand 198 states and 233 transitions. Second operand has 8 states, 8 states have (on average 4.75) internal successors, (38), 8 states have internal predecessors, (38), 4 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) [2022-11-03 02:04:05,100 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:05,100 INFO L93 Difference]: Finished difference Result 337 states and 401 transitions. [2022-11-03 02:04:05,101 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-03 02:04:05,101 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 8 states have internal predecessors, (38), 4 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) Word has length 53 [2022-11-03 02:04:05,101 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:05,103 INFO L225 Difference]: With dead ends: 337 [2022-11-03 02:04:05,103 INFO L226 Difference]: Without dead ends: 206 [2022-11-03 02:04:05,104 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=30, Invalid=42, Unknown=0, NotChecked=0, Total=72 [2022-11-03 02:04:05,107 INFO L413 NwaCegarLoop]: 30 mSDtfsCounter, 73 mSDsluCounter, 73 mSDsCounter, 0 mSdLazyCounter, 107 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 77 SdHoareTripleChecker+Valid, 90 SdHoareTripleChecker+Invalid, 133 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 107 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:05,107 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [77 Valid, 90 Invalid, 133 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 107 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 02:04:05,108 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 206 states. [2022-11-03 02:04:05,152 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 206 to 198. [2022-11-03 02:04:05,153 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 198 states, 132 states have (on average 1.1742424242424243) internal successors, (155), 146 states have internal predecessors, (155), 33 states have call successors, (33), 30 states have call predecessors, (33), 32 states have return successors, (44), 32 states have call predecessors, (44), 33 states have call successors, (44) [2022-11-03 02:04:05,154 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 232 transitions. [2022-11-03 02:04:05,155 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 232 transitions. Word has length 53 [2022-11-03 02:04:05,155 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:05,155 INFO L495 AbstractCegarLoop]: Abstraction has 198 states and 232 transitions. [2022-11-03 02:04:05,156 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 8 states have internal predecessors, (38), 4 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 4 states have call successors, (6) [2022-11-03 02:04:05,156 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 232 transitions. [2022-11-03 02:04:05,157 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 59 [2022-11-03 02:04:05,158 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:05,158 INFO L195 NwaCegarLoop]: trace histogram [4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:05,158 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-03 02:04:05,158 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:05,159 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:05,159 INFO L85 PathProgramCache]: Analyzing trace with hash 1457575136, now seen corresponding path program 1 times [2022-11-03 02:04:05,159 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:05,159 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [417114465] [2022-11-03 02:04:05,160 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:05,160 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:05,201 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:05,669 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 3 proven. 13 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-11-03 02:04:05,670 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:05,670 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [417114465] [2022-11-03 02:04:05,670 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [417114465] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 02:04:05,670 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1938431220] [2022-11-03 02:04:05,670 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:05,671 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:04:05,673 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:04:05,676 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 02:04:05,696 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 02:04:05,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:05,801 INFO L263 TraceCheckSpWp]: Trace formula consists of 451 conjuncts, 28 conjunts are in the unsatisfiable core [2022-11-03 02:04:05,808 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 02:04:06,241 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 13 proven. 13 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2022-11-03 02:04:06,241 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 02:04:06,853 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-11-03 02:04:06,854 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1938431220] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 02:04:06,854 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1025980569] [2022-11-03 02:04:06,876 INFO L159 IcfgInterpreter]: Started Sifa with 34 locations of interest [2022-11-03 02:04:06,876 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 02:04:06,880 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 02:04:06,886 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 02:04:06,886 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 02:04:28,791 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 33 for LOIs [2022-11-03 02:04:28,796 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 55 for LOIs [2022-11-03 02:04:29,359 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 43 for LOIs [2022-11-03 02:04:29,366 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 30 for LOIs [2022-11-03 02:04:29,368 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 02:04:36,492 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '4761#(and (<= 0 |timeShift_isHighWaterLevel_~retValue_acc~6#1|) (<= |timeShift_isHighWaterLevel_#res#1| 1) (<= 0 |timeShift_isHighWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 0)) (<= 0 |timeShift_isHighWaterSensorDry_~retValue_acc~9#1|) (= |timeShift_getWaterLevel_~retValue_acc~8#1| ~waterLevel~0) (<= ~pumpRunning~0 1) (<= 0 |timeShift_processEnvironment_~tmp~5#1|) (<= |timeShift_isHighWaterSensorDry_#res#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| 2)) (= ~methaneLevelCritical~0 0) (<= 0 |old(~switchedOnBeforeTS~0)|) (= ~head~0.offset 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |timeShift_isHighWaterSensorDry_#res#1|) (<= |old(~switchedOnBeforeTS~0)| 0) (= |old(~pumpRunning~0)| 0) (<= |timeShift_isHighWaterSensorDry_~retValue_acc~9#1| 1) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (<= 0 |timeShift_isHighWaterLevel_~tmp___0~1#1|) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_processEnvironment_~tmp~5#1| 1) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (<= |timeShift_isHighWaterLevel_~retValue_acc~6#1| 1) (= |#NULL.offset| 0) (<= |timeShift_isHighWaterLevel_~tmp~7#1| 1) (<= |timeShift_isHighWaterLevel_~tmp___0~1#1| 1) (<= 0 |timeShift_isHighWaterLevel_~tmp~7#1|) (= ~switchedOnBeforeTS~0 0) (<= |timeShift_getWaterLevel_~retValue_acc~8#1| 2147483647) (<= 0 |#StackHeapBarrier|) (= |timeShift_getWaterLevel_~retValue_acc~8#1| |timeShift_getWaterLevel_#res#1|) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 02:04:36,493 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 02:04:36,493 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 02:04:36,493 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 9, 9] total 17 [2022-11-03 02:04:36,493 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1061740442] [2022-11-03 02:04:36,494 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 02:04:36,494 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 17 states [2022-11-03 02:04:36,495 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:36,495 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 17 interpolants. [2022-11-03 02:04:36,496 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=205, Invalid=1601, Unknown=0, NotChecked=0, Total=1806 [2022-11-03 02:04:36,496 INFO L87 Difference]: Start difference. First operand 198 states and 232 transitions. Second operand has 17 states, 14 states have (on average 4.857142857142857) internal successors, (68), 16 states have internal predecessors, (68), 6 states have call successors, (16), 6 states have call predecessors, (16), 8 states have return successors, (15), 6 states have call predecessors, (15), 6 states have call successors, (15) [2022-11-03 02:04:37,994 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:37,994 INFO L93 Difference]: Finished difference Result 505 states and 633 transitions. [2022-11-03 02:04:37,995 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 30 states. [2022-11-03 02:04:37,995 INFO L78 Accepts]: Start accepts. Automaton has has 17 states, 14 states have (on average 4.857142857142857) internal successors, (68), 16 states have internal predecessors, (68), 6 states have call successors, (16), 6 states have call predecessors, (16), 8 states have return successors, (15), 6 states have call predecessors, (15), 6 states have call successors, (15) Word has length 58 [2022-11-03 02:04:37,996 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:37,998 INFO L225 Difference]: With dead ends: 505 [2022-11-03 02:04:37,999 INFO L226 Difference]: Without dead ends: 407 [2022-11-03 02:04:38,001 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 214 GetRequests, 146 SyntacticMatches, 5 SemanticMatches, 63 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1374 ImplicationChecksByTransitivity, 8.1s TimeCoverageRelationStatistics Valid=503, Invalid=3657, Unknown=0, NotChecked=0, Total=4160 [2022-11-03 02:04:38,002 INFO L413 NwaCegarLoop]: 79 mSDtfsCounter, 391 mSDsluCounter, 338 mSDsCounter, 0 mSdLazyCounter, 509 mSolverCounterSat, 282 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 394 SdHoareTripleChecker+Valid, 365 SdHoareTripleChecker+Invalid, 791 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 282 IncrementalHoareTripleChecker+Valid, 509 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:38,002 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [394 Valid, 365 Invalid, 791 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [282 Valid, 509 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-03 02:04:38,004 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 407 states. [2022-11-03 02:04:38,048 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 407 to 219. [2022-11-03 02:04:38,050 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 219 states, 145 states have (on average 1.1793103448275861) internal successors, (171), 162 states have internal predecessors, (171), 37 states have call successors, (37), 34 states have call predecessors, (37), 36 states have return successors, (53), 36 states have call predecessors, (53), 37 states have call successors, (53) [2022-11-03 02:04:38,053 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 219 states to 219 states and 261 transitions. [2022-11-03 02:04:38,053 INFO L78 Accepts]: Start accepts. Automaton has 219 states and 261 transitions. Word has length 58 [2022-11-03 02:04:38,054 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:38,054 INFO L495 AbstractCegarLoop]: Abstraction has 219 states and 261 transitions. [2022-11-03 02:04:38,054 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 17 states, 14 states have (on average 4.857142857142857) internal successors, (68), 16 states have internal predecessors, (68), 6 states have call successors, (16), 6 states have call predecessors, (16), 8 states have return successors, (15), 6 states have call predecessors, (15), 6 states have call successors, (15) [2022-11-03 02:04:38,055 INFO L276 IsEmpty]: Start isEmpty. Operand 219 states and 261 transitions. [2022-11-03 02:04:38,056 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 73 [2022-11-03 02:04:38,056 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:04:38,057 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:38,101 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-03 02:04:38,276 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:04:38,276 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:04:38,276 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:04:38,276 INFO L85 PathProgramCache]: Analyzing trace with hash 1782299737, now seen corresponding path program 1 times [2022-11-03 02:04:38,277 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:04:38,277 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [573085982] [2022-11-03 02:04:38,277 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:04:38,277 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:04:38,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:04:38,471 INFO L134 CoverageAnalysis]: Checked inductivity of 60 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-11-03 02:04:38,471 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:04:38,472 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [573085982] [2022-11-03 02:04:38,472 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [573085982] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:04:38,472 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:04:38,472 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 02:04:38,472 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [590221640] [2022-11-03 02:04:38,473 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:04:38,473 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 02:04:38,473 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:04:38,473 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 02:04:38,474 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=6, Invalid=6, Unknown=0, NotChecked=0, Total=12 [2022-11-03 02:04:38,474 INFO L87 Difference]: Start difference. First operand 219 states and 261 transitions. Second operand has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (7), 4 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-03 02:04:38,567 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:04:38,567 INFO L93 Difference]: Finished difference Result 348 states and 417 transitions. [2022-11-03 02:04:38,568 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 02:04:38,569 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (7), 4 states have call predecessors, (7), 4 states have call successors, (7) Word has length 72 [2022-11-03 02:04:38,569 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:04:38,569 INFO L225 Difference]: With dead ends: 348 [2022-11-03 02:04:38,569 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 02:04:38,570 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=6, Invalid=6, Unknown=0, NotChecked=0, Total=12 [2022-11-03 02:04:38,571 INFO L413 NwaCegarLoop]: 55 mSDtfsCounter, 29 mSDsluCounter, 66 mSDsCounter, 0 mSdLazyCounter, 53 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 29 SdHoareTripleChecker+Valid, 109 SdHoareTripleChecker+Invalid, 57 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 53 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 02:04:38,571 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [29 Valid, 109 Invalid, 57 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 53 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 02:04:38,571 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 02:04:38,572 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 02:04:38,572 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 02:04:38,572 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 02:04:38,572 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 72 [2022-11-03 02:04:38,572 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:04:38,572 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 02:04:38,572 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 11.0) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (7), 4 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-03 02:04:38,572 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 02:04:38,573 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 02:04:38,575 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 02:04:38,575 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-11-03 02:04:38,577 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 02:04:43,269 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 629 635) no Hoare annotation was computed. [2022-11-03 02:04:43,270 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 629 635) the Hoare annotation is: true [2022-11-03 02:04:43,270 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 814 825) the Hoare annotation is: true [2022-11-03 02:04:43,270 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 814 825) no Hoare annotation was computed. [2022-11-03 02:04:43,270 INFO L899 garLoopResultBuilder]: For program point L609-2(lines 605 627) no Hoare annotation was computed. [2022-11-03 02:04:43,270 INFO L899 garLoopResultBuilder]: For program point L915(lines 915 921) no Hoare annotation was computed. [2022-11-03 02:04:43,271 INFO L895 garLoopResultBuilder]: At program point L651(line 651) the Hoare annotation is: (let ((.cse1 (= |old(~pumpRunning~0)| 0)) (.cse3 (not (= |old(~waterLevel~0)| 1))) (.cse0 (< |old(~waterLevel~0)| 2)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (<= |timeShift_processEnvironment_~tmp~5#1| 0)) (.cse5 (< 0 (+ |timeShift_processEnvironment_~tmp~5#1| 1))) (.cse6 (= ~pumpRunning~0 0)) (.cse7 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or .cse0 .cse1 .cse2) (or (and .cse3 (= |old(~switchedOnBeforeTS~0)| 0)) .cse1) (or (and .cse4 .cse5 .cse6 (= ~waterLevel~0 1) .cse7) .cse3) (not (= 0 ~systemActive~0)) (or .cse0 .cse2 (and .cse4 .cse5 .cse6 (= |old(~waterLevel~0)| ~waterLevel~0) .cse7)))) [2022-11-03 02:04:43,271 INFO L895 garLoopResultBuilder]: At program point L656(line 656) the Hoare annotation is: (let ((.cse5 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (not .cse5)) (.cse3 (not (= |old(~waterLevel~0)| 1)))) (and (or (< |old(~waterLevel~0)| 2) (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2) (or (and .cse3 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse0 (let ((.cse4 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse4) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse4))) .cse1) .cse5) (or .cse6 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse6 .cse3) (not (= 0 ~systemActive~0))))) [2022-11-03 02:04:43,272 INFO L895 garLoopResultBuilder]: At program point L912(line 912) the Hoare annotation is: (let ((.cse12 (= |old(~pumpRunning~0)| 0)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse7 (= ~pumpRunning~0 0)) (.cse8 (= 0 ~systemActive~0))) (let ((.cse1 (= ~waterLevel~0 1)) (.cse9 (not .cse8)) (.cse6 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not .cse7)) (.cse3 (and .cse8 .cse2)) (.cse5 (not .cse12)) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse10 (and .cse7 .cse8))) (and (or (< |old(~waterLevel~0)| 2) (and .cse0 .cse1 .cse2) .cse3 .cse4) (or .cse5 .cse6 (and .cse7 (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| ~waterLevel~0) .cse1 .cse2) (and .cse7 .cse8 .cse1 .cse2)) (or .cse5 .cse9 .cse10) (or .cse3 .cse9) (or (and .cse6 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse0 (let ((.cse11 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse11) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse11))) .cse2) .cse12 .cse3) (or .cse5 .cse4 .cse10 (not (<= 2 |old(~waterLevel~0)|)))))) [2022-11-03 02:04:43,272 INFO L895 garLoopResultBuilder]: At program point L656-1(lines 637 661) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse9 (= |old(~pumpRunning~0)| 0))) (let ((.cse3 (not .cse9)) (.cse4 (not (= |old(~waterLevel~0)| 1))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse7 (not .cse0)) (.cse1 (= ~waterLevel~0 1)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse6 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and (<= |timeShift_processEnvironment_~tmp~5#1| 0) (< 0 (+ |timeShift_processEnvironment_~tmp~5#1| 1)) .cse0 .cse1 .cse2) .cse3 .cse4) (or .cse3 .cse5 .cse6 (not (<= 2 |old(~waterLevel~0)|))) (or (and .cse4 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse7 (let ((.cse8 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse8) .cse5) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse8))) .cse2) .cse9) (or (< |old(~waterLevel~0)| 2) .cse9 (and .cse7 .cse1 .cse2) .cse6) (not (= 0 ~systemActive~0))))) [2022-11-03 02:04:43,273 INFO L899 garLoopResultBuilder]: For program point L912-1(line 912) no Hoare annotation was computed. [2022-11-03 02:04:43,273 INFO L895 garLoopResultBuilder]: At program point L971(line 971) the Hoare annotation is: (and (not (= |old(~waterLevel~0)| 1)) (or (= |old(~pumpRunning~0)| 0) (= |old(~switchedOnBeforeTS~0)| 0)) (or (< |old(~waterLevel~0)| 2) (not (<= |old(~waterLevel~0)| 2))) (not (= 0 ~systemActive~0))) [2022-11-03 02:04:43,273 INFO L895 garLoopResultBuilder]: At program point L616-1(lines 616 622) the Hoare annotation is: (let ((.cse13 (= 0 ~systemActive~0))) (let ((.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse14 (= |old(~pumpRunning~0)| 0)) (.cse11 (not .cse13)) (.cse10 (= ~pumpRunning~0 0))) (let ((.cse1 (not .cse10)) (.cse5 (and .cse14 .cse11)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse7 (= ~waterLevel~0 1)) (.cse6 (and .cse13 .cse4)) (.cse9 (not .cse14)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse12 (and .cse10 .cse13))) (and (or (and .cse0 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse1 (let ((.cse2 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse2) .cse3) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2))) .cse4) .cse5 .cse6) (or (< |old(~waterLevel~0)| 2) (and .cse1 .cse7 .cse4) .cse5 .cse6 .cse8) (or .cse9 .cse0 (and .cse10 .cse7 .cse4)) (or .cse9 .cse11 .cse12) (or .cse6 .cse11) (or .cse9 .cse3 .cse8 .cse12 (not (<= 2 |old(~waterLevel~0)|))))))) [2022-11-03 02:04:43,274 INFO L895 garLoopResultBuilder]: At program point L645(lines 645 653) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (= |old(~pumpRunning~0)| 0)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (not (= |old(~waterLevel~0)| 1)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (and .cse3 (= |old(~waterLevel~0)| ~waterLevel~0) .cse4) .cse2) (or (and .cse5 (= |old(~switchedOnBeforeTS~0)| 0)) .cse1) (or (and (<= |timeShift_processEnvironment_~tmp~5#1| 0) (< 0 (+ |timeShift_processEnvironment_~tmp~5#1| 1)) .cse3 (= ~waterLevel~0 1) .cse4) .cse5) (not (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,274 INFO L895 garLoopResultBuilder]: At program point L897(line 897) the Hoare annotation is: (let ((.cse12 (= 0 ~systemActive~0))) (let ((.cse2 (not .cse12)) (.cse1 (= ~pumpRunning~0 0)) (.cse11 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse11)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse10 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse4 (or (not .cse1) .cse12)) (.cse9 (not (= ~switchedOnBeforeTS~0 0))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (= ~waterLevel~0 1)) (.cse3 (and .cse11 .cse2))) (and (or .cse0 .cse1 .cse2) (or (< |old(~waterLevel~0)| 2) .cse3 (and .cse4 .cse5) .cse6) (or .cse0 .cse7 (and .cse1 .cse8)) (or .cse5 .cse8 .cse2) (or .cse9 .cse2 .cse10) (or .cse0 (and .cse1 .cse5) .cse6 (not (<= 2 |old(~waterLevel~0)|))) (or (and .cse7 .cse10) (and .cse4 (or (and .cse9 .cse5) (and .cse5 .cse8))) .cse3))))) [2022-11-03 02:04:43,275 INFO L895 garLoopResultBuilder]: At program point L641(lines 641 658) the Hoare annotation is: (let ((.cse9 (= ~pumpRunning~0 0))) (let ((.cse4 (= |old(~pumpRunning~0)| 0)) (.cse1 (not .cse9)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse2 (or (and .cse9 .cse6) (and .cse1 (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse10) .cse6) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse10)))))) (.cse5 (not .cse4)) (.cse7 (or (and .cse1 (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0)) (and .cse9 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)))) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse8 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and .cse0 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse1 .cse2 .cse3) .cse4) (or .cse5 .cse0 (and .cse2 (= ~waterLevel~0 1) .cse3)) (or (and .cse6 .cse7 .cse3) .cse5 .cse8 (not (<= 2 |old(~waterLevel~0)|))) (or (and .cse1 .cse7 .cse3) (< |old(~waterLevel~0)| 2) .cse4 .cse8) (not (= 0 ~systemActive~0)))))) [2022-11-03 02:04:43,275 INFO L895 garLoopResultBuilder]: At program point L897-1(line 897) the Hoare annotation is: (let ((.cse6 (= 0 ~systemActive~0))) (let ((.cse1 (= ~pumpRunning~0 0)) (.cse12 (= |old(~pumpRunning~0)| 0)) (.cse2 (not .cse6))) (let ((.cse4 (< |old(~waterLevel~0)| 2)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (and .cse12 .cse2)) (.cse3 (not .cse1)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not .cse12)) (.cse10 (not (= |old(~waterLevel~0)| 1))) (.cse8 (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__2_#t~ret49#1|)) (.cse11 (= ~waterLevel~0 1))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6 .cse7) (or .cse4 .cse7 (and .cse8 .cse9)) (or .cse0 .cse1 .cse7 (not (<= 2 |old(~waterLevel~0)|))) (or (and .cse10 (= |old(~switchedOnBeforeTS~0)| 0)) .cse5 (and (or .cse3 .cse6) .cse8 .cse9)) (or (and .cse8 (or .cse9 .cse11)) .cse2) (or .cse0 .cse10 (and .cse1 .cse8 .cse11)))))) [2022-11-03 02:04:43,276 INFO L899 garLoopResultBuilder]: For program point L914(lines 914 924) no Hoare annotation was computed. [2022-11-03 02:04:43,276 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 602 628) the Hoare annotation is: (let ((.cse12 (= 0 ~systemActive~0))) (let ((.cse2 (not .cse12)) (.cse1 (= ~pumpRunning~0 0)) (.cse11 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse11)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse10 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse4 (or (not .cse1) .cse12)) (.cse9 (not (= ~switchedOnBeforeTS~0 0))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (= ~waterLevel~0 1)) (.cse3 (and .cse11 .cse2))) (and (or .cse0 .cse1 .cse2) (or (< |old(~waterLevel~0)| 2) .cse3 (and .cse4 .cse5) .cse6) (or .cse0 .cse7 (and .cse1 .cse8)) (or .cse5 .cse8 .cse2) (or .cse9 .cse2 .cse10) (or .cse0 (and .cse1 .cse5) .cse6 (not (<= 2 |old(~waterLevel~0)|))) (or (and .cse7 .cse10) (and .cse4 (or (and .cse9 .cse5) (and .cse5 .cse8))) .cse3))))) [2022-11-03 02:04:43,276 INFO L899 garLoopResultBuilder]: For program point L910(lines 910 927) no Hoare annotation was computed. [2022-11-03 02:04:43,277 INFO L895 garLoopResultBuilder]: At program point L910-1(lines 902 930) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse9 (= |old(~pumpRunning~0)| 0))) (let ((.cse3 (not (= |old(~waterLevel~0)| 1))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse9)) (.cse11 (and .cse4 .cse0)) (.cse6 (not (= ~switchedOnBeforeTS~0 0))) (.cse7 (not .cse4)) (.cse1 (= ~waterLevel~0 1)) (.cse10 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and .cse0 .cse1) .cse2 .cse3 (and .cse4 (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| ~waterLevel~0) .cse5)) (or (and .cse3 (= |old(~switchedOnBeforeTS~0)| 0)) (and .cse6 .cse7 (let ((.cse8 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse8) .cse5) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse8)))) .cse9 .cse0) (or .cse2 .cse10 .cse11 (not (<= 2 |old(~waterLevel~0)|)) (and (< 1 |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1|) .cse5 (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| 2))) (or .cse2 (not .cse0) .cse11) (or (and .cse6 .cse7 .cse1) (< |old(~waterLevel~0)| 2) .cse9 .cse0 .cse10)))) [2022-11-03 02:04:43,277 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 602 628) no Hoare annotation was computed. [2022-11-03 02:04:43,277 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 971) no Hoare annotation was computed. [2022-11-03 02:04:43,277 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 418 447) no Hoare annotation was computed. [2022-11-03 02:04:43,278 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 418 447) the Hoare annotation is: true [2022-11-03 02:04:43,278 INFO L902 garLoopResultBuilder]: At program point L443(lines 418 447) the Hoare annotation is: true [2022-11-03 02:04:43,278 INFO L899 garLoopResultBuilder]: For program point L439(line 439) no Hoare annotation was computed. [2022-11-03 02:04:43,281 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2022-11-03 02:04:43,287 INFO L902 garLoopResultBuilder]: At program point L432-1(lines 432 436) the Hoare annotation is: true [2022-11-03 02:04:43,288 INFO L902 garLoopResultBuilder]: At program point L428-2(lines 428 442) the Hoare annotation is: true [2022-11-03 02:04:43,288 INFO L902 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: true [2022-11-03 02:04:43,288 INFO L899 garLoopResultBuilder]: For program point L424-1(line 424) no Hoare annotation was computed. [2022-11-03 02:04:43,288 INFO L899 garLoopResultBuilder]: For program point L543(lines 543 549) no Hoare annotation was computed. [2022-11-03 02:04:43,288 INFO L899 garLoopResultBuilder]: For program point L543-1(lines 543 549) no Hoare annotation was computed. [2022-11-03 02:04:43,288 INFO L895 garLoopResultBuilder]: At program point L581(lines 532 582) the Hoare annotation is: false [2022-11-03 02:04:43,288 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 02:04:43,288 INFO L895 garLoopResultBuilder]: At program point L569-2(lines 563 576) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (not (= ~pumpRunning~0 0)) .cse0) (and .cse0 (= ~waterLevel~0 1)) (and .cse0 (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,289 INFO L899 garLoopResultBuilder]: For program point L553(lines 553 559) no Hoare annotation was computed. [2022-11-03 02:04:43,289 INFO L895 garLoopResultBuilder]: At program point L553-1(lines 553 559) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (not (= ~pumpRunning~0 0)) .cse0) (and .cse0 (= ~waterLevel~0 1)) (and .cse0 (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,289 INFO L895 garLoopResultBuilder]: At program point L578(lines 533 580) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (not (= ~pumpRunning~0 0)) .cse0) (and .cse0 (= ~waterLevel~0 1)) (and .cse0 (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,289 INFO L895 garLoopResultBuilder]: At program point L545(line 545) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (not (= ~pumpRunning~0 0)) .cse0) (and .cse0 (= ~waterLevel~0 1)) (and .cse0 (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,289 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 02:04:43,290 INFO L895 garLoopResultBuilder]: At program point L508(lines 508 515) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2022-11-03 02:04:43,290 INFO L902 garLoopResultBuilder]: At program point L508-2(lines 508 515) the Hoare annotation is: true [2022-11-03 02:04:43,290 INFO L899 garLoopResultBuilder]: For program point L534(lines 533 580) no Hoare annotation was computed. [2022-11-03 02:04:43,290 INFO L895 garLoopResultBuilder]: At program point L555(line 555) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (not (= ~pumpRunning~0 0)) .cse0) (and .cse0 (= ~waterLevel~0 1)) (and .cse0 (= 0 ~systemActive~0)))) [2022-11-03 02:04:43,290 INFO L902 garLoopResultBuilder]: At program point L584(lines 523 588) the Hoare annotation is: true [2022-11-03 02:04:43,290 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 802 813) no Hoare annotation was computed. [2022-11-03 02:04:43,290 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 802 813) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (and (not (= |old(~waterLevel~0)| 1)) (or (< |old(~waterLevel~0)| 2) (not (<= |old(~waterLevel~0)| 2)))) .cse0) (or .cse0 (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) (or (= ~pumpRunning~0 0) .cse0 (= ~switchedOnBeforeTS~0 0)))) [2022-11-03 02:04:43,290 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 707 715) no Hoare annotation was computed. [2022-11-03 02:04:43,291 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 707 715) the Hoare annotation is: true [2022-11-03 02:04:43,294 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:04:43,296 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 02:04:43,328 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 02:04:43 BoogieIcfgContainer [2022-11-03 02:04:43,343 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 02:04:43,344 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 02:04:43,344 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 02:04:43,344 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 02:04:43,345 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:04:00" (3/4) ... [2022-11-03 02:04:43,348 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 02:04:43,360 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 02:04:43,360 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 02:04:43,360 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 02:04:43,361 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 02:04:43,361 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 02:04:43,361 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-03 02:04:43,368 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 79 nodes and edges [2022-11-03 02:04:43,372 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 29 nodes and edges [2022-11-03 02:04:43,372 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-03 02:04:43,373 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 02:04:43,374 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 02:04:43,374 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 02:04:43,375 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 02:04:43,398 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && ((((!(pumpRunning == 0) || \old(waterLevel) < 2) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((\old(waterLevel) < 2 || !(\old(waterLevel) <= 2)) || (pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel))) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (((!(pumpRunning == 0) || 0 == systemActive) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel))) && ((pumpRunning == aux-isPumpRunning()-aux && (\old(waterLevel) == waterLevel || waterLevel == 1)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && waterLevel == 1)) [2022-11-03 02:04:43,399 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (0 == systemActive && pumpRunning == switchedOnBeforeTS)) && ((((\old(waterLevel) < 2 || ((!(pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS)) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (0 == systemActive && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && waterLevel == 1) && pumpRunning == switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && 0 == systemActive))) && ((0 == systemActive && pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 0 == systemActive)) || !(2 <= \old(waterLevel))) [2022-11-03 02:04:43,399 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((0 == systemActive && waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && tmp <= waterLevel) && \old(waterLevel) == waterLevel)) && ((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(pumpRunning) == 0) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 0 == systemActive)) || !(2 <= \old(waterLevel))) || ((1 < tmp && \old(waterLevel) == waterLevel) && tmp <= 2))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && 0 == systemActive))) && ((((((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && waterLevel == 1) || \old(waterLevel) < 2) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-03 02:04:43,399 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))))) && pumpRunning == switchedOnBeforeTS)) || \old(pumpRunning) == 0) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS))) && (((((\old(waterLevel) == waterLevel && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(pumpRunning == 0) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS) || \old(waterLevel) < 2) || \old(pumpRunning) == 0) || !(\old(waterLevel) <= 2))) && !(0 == systemActive) [2022-11-03 02:04:43,400 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(waterLevel) == 1) && (\old(pumpRunning) == 0 || \old(switchedOnBeforeTS) == 0)) && (\old(waterLevel) < 2 || !(\old(waterLevel) <= 2))) && !(0 == systemActive) [2022-11-03 02:04:43,400 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((tmp <= 0 && 0 < tmp + 1) && pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) && (((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || \old(pumpRunning) == 0)) && (((\old(waterLevel) < 2 || \old(pumpRunning) == 0) || ((!(pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && !(0 == systemActive) [2022-11-03 02:04:43,401 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((\old(waterLevel) < 2 || \old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) && ((\old(waterLevel) < 2 || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && ((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || \old(pumpRunning) == 0)) && (((((tmp <= 0 && 0 < tmp + 1) && pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(waterLevel) == 1))) && !(0 == systemActive) [2022-11-03 02:04:43,423 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 02:04:43,423 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 02:04:43,424 INFO L158 Benchmark]: Toolchain (without parser) took 44695.65ms. Allocated memory was 104.9MB in the beginning and 432.0MB in the end (delta: 327.2MB). Free memory was 73.1MB in the beginning and 382.1MB in the end (delta: -309.1MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,424 INFO L158 Benchmark]: CDTParser took 0.36ms. Allocated memory is still 104.9MB. Free memory is still 60.7MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 02:04:43,425 INFO L158 Benchmark]: CACSL2BoogieTranslator took 598.38ms. Allocated memory is still 104.9MB. Free memory was 73.1MB in the beginning and 71.3MB in the end (delta: 1.7MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,425 INFO L158 Benchmark]: Boogie Procedure Inliner took 84.14ms. Allocated memory is still 104.9MB. Free memory was 71.3MB in the beginning and 68.9MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,425 INFO L158 Benchmark]: Boogie Preprocessor took 35.04ms. Allocated memory is still 104.9MB. Free memory was 68.9MB in the beginning and 66.9MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,426 INFO L158 Benchmark]: RCFGBuilder took 1053.56ms. Allocated memory was 104.9MB in the beginning and 138.4MB in the end (delta: 33.6MB). Free memory was 66.9MB in the beginning and 98.1MB in the end (delta: -31.2MB). Peak memory consumption was 24.1MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,426 INFO L158 Benchmark]: TraceAbstraction took 42835.11ms. Allocated memory was 138.4MB in the beginning and 432.0MB in the end (delta: 293.6MB). Free memory was 97.5MB in the beginning and 387.4MB in the end (delta: -289.9MB). Peak memory consumption was 249.1MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,427 INFO L158 Benchmark]: Witness Printer took 79.50ms. Allocated memory is still 432.0MB. Free memory was 387.4MB in the beginning and 382.1MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-03 02:04:43,428 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.36ms. Allocated memory is still 104.9MB. Free memory is still 60.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 598.38ms. Allocated memory is still 104.9MB. Free memory was 73.1MB in the beginning and 71.3MB in the end (delta: 1.7MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 84.14ms. Allocated memory is still 104.9MB. Free memory was 71.3MB in the beginning and 68.9MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 35.04ms. Allocated memory is still 104.9MB. Free memory was 68.9MB in the beginning and 66.9MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 1053.56ms. Allocated memory was 104.9MB in the beginning and 138.4MB in the end (delta: 33.6MB). Free memory was 66.9MB in the beginning and 98.1MB in the end (delta: -31.2MB). Peak memory consumption was 24.1MB. Max. memory is 16.1GB. * TraceAbstraction took 42835.11ms. Allocated memory was 138.4MB in the beginning and 432.0MB in the end (delta: 293.6MB). Free memory was 97.5MB in the beginning and 387.4MB in the end (delta: -289.9MB). Peak memory consumption was 249.1MB. Max. memory is 16.1GB. * Witness Printer took 79.50ms. Allocated memory is still 432.0MB. Free memory was 387.4MB in the beginning and 382.1MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 971]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 51 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 42.7s, OverallIterations: 9, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 859 SdHoareTripleChecker+Valid, 1.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 839 mSDsluCounter, 1653 SdHoareTripleChecker+Invalid, 1.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1434 mSDsCounter, 442 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1586 IncrementalHoareTripleChecker+Invalid, 2028 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 442 mSolverCounterUnsat, 488 mSDtfsCounter, 1586 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 304 GetRequests, 176 SyntacticMatches, 5 SemanticMatches, 123 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1525 ImplicationChecksByTransitivity, 8.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=231occurred in iteration=5, InterpolantAutomatonStates: 101, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 9 MinimizatonAttempts, 329 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 31 LocationsWithAnnotation, 646 PreInvPairs, 812 NumberOfFragments, 1663 HoareAnnotationTreeSize, 646 FomulaSimplifications, 5613 FormulaSimplificationTreeSizeReduction, 0.5s HoareSimplificationTime, 31 FomulaSimplificationsInter, 14121 FormulaSimplificationTreeSizeReductionInter, 4.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 3.4s InterpolantComputationTime, 412 NumberOfCodeBlocks, 412 NumberOfCodeBlocksAsserted, 10 NumberOfCheckSat, 459 ConstructedInterpolants, 0 QuantifiedInterpolants, 1697 SizeOfPredicates, 9 NumberOfNonLiveVariables, 451 ConjunctsInSsa, 28 ConjunctsInUnsatCore, 11 InterpolantComputations, 8 PerfectInterpolantSequences, 177/204 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 897]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && ((((!(pumpRunning == 0) || \old(waterLevel) < 2) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((\old(waterLevel) < 2 || !(\old(waterLevel) <= 2)) || (pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel))) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (((!(pumpRunning == 0) || 0 == systemActive) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel))) && ((pumpRunning == aux-isPumpRunning()-aux && (\old(waterLevel) == waterLevel || waterLevel == 1)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && waterLevel == 1)) - InvariantResult [Line: 523]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 641]: Loop Invariant Derived loop invariant: ((((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))))) && pumpRunning == switchedOnBeforeTS)) || \old(pumpRunning) == 0) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS))) && (((((\old(waterLevel) == waterLevel && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(pumpRunning == 0) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS) || \old(waterLevel) < 2) || \old(pumpRunning) == 0) || !(\old(waterLevel) <= 2))) && !(0 == systemActive) - InvariantResult [Line: 553]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) || ((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && splverifierCounter == 0)) || (splverifierCounter == 0 && waterLevel == 1)) || (splverifierCounter == 0 && 0 == systemActive) - InvariantResult [Line: 902]: Loop Invariant Derived loop invariant: (((((((0 == systemActive && waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && tmp <= waterLevel) && \old(waterLevel) == waterLevel)) && ((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(pumpRunning) == 0) || 0 == systemActive)) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 0 == systemActive)) || !(2 <= \old(waterLevel))) || ((1 < tmp && \old(waterLevel) == waterLevel) && tmp <= 2))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && 0 == systemActive))) && ((((((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && waterLevel == 1) || \old(waterLevel) < 2) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 418]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 428]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 971]: Loop Invariant Derived loop invariant: ((!(\old(waterLevel) == 1) && (\old(pumpRunning) == 0 || \old(switchedOnBeforeTS) == 0)) && (\old(waterLevel) < 2 || !(\old(waterLevel) <= 2))) && !(0 == systemActive) - InvariantResult [Line: 533]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) || ((!(switchedOnBeforeTS == 0) && !(pumpRunning == 0)) && splverifierCounter == 0)) || (splverifierCounter == 0 && waterLevel == 1)) || (splverifierCounter == 0 && 0 == systemActive) - InvariantResult [Line: 616]: Loop Invariant Derived loop invariant: ((((((((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (0 == systemActive && pumpRunning == switchedOnBeforeTS)) && ((((\old(waterLevel) < 2 || ((!(pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS)) || (\old(pumpRunning) == 0 && !(0 == systemActive))) || (0 == systemActive && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((pumpRunning == 0 && waterLevel == 1) && pumpRunning == switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && 0 == systemActive))) && ((0 == systemActive && pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || (pumpRunning == 0 && 0 == systemActive)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 508]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && pumpRunning == switchedOnBeforeTS - InvariantResult [Line: 532]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 645]: Loop Invariant Derived loop invariant: (((((\old(waterLevel) < 2 || \old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) && ((\old(waterLevel) < 2 || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && ((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || \old(pumpRunning) == 0)) && (((((tmp <= 0 && 0 < tmp + 1) && pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(waterLevel) == 1))) && !(0 == systemActive) - InvariantResult [Line: 637]: Loop Invariant Derived loop invariant: (((((((((tmp <= 0 && 0 < tmp + 1) && pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) && (((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) && \old(switchedOnBeforeTS) == 0) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || \old(pumpRunning) == 0)) && (((\old(waterLevel) < 2 || \old(pumpRunning) == 0) || ((!(pumpRunning == 0) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2))) && !(0 == systemActive) - InvariantResult [Line: 508]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-03 02:04:43,481 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_32978a9d-7f76-4c04-abe5-94b75af9f371/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE