./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 73b8e020dd9d30fdd676c81009d4f1b850aa716d63ef29ce3d475a261546f853 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 03:45:30,085 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 03:45:30,088 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 03:45:30,142 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 03:45:30,143 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 03:45:30,147 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 03:45:30,149 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 03:45:30,150 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 03:45:30,152 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 03:45:30,152 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 03:45:30,153 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 03:45:30,154 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 03:45:30,155 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 03:45:30,156 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 03:45:30,157 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 03:45:30,158 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 03:45:30,165 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 03:45:30,172 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 03:45:30,177 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 03:45:30,179 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 03:45:30,180 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 03:45:30,184 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 03:45:30,186 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 03:45:30,188 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 03:45:30,193 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 03:45:30,194 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 03:45:30,194 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 03:45:30,195 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 03:45:30,196 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 03:45:30,196 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 03:45:30,197 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 03:45:30,198 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 03:45:30,198 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 03:45:30,199 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 03:45:30,200 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 03:45:30,200 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 03:45:30,201 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 03:45:30,201 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 03:45:30,202 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 03:45:30,202 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 03:45:30,203 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 03:45:30,204 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 03:45:30,233 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 03:45:30,233 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 03:45:30,234 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 03:45:30,234 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 03:45:30,235 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 03:45:30,235 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 03:45:30,235 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 03:45:30,235 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 03:45:30,235 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 03:45:30,236 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 03:45:30,236 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 03:45:30,236 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 03:45:30,236 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 03:45:30,236 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 03:45:30,237 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 03:45:30,237 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 03:45:30,237 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 03:45:30,237 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 03:45:30,238 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 03:45:30,238 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 03:45:30,238 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 03:45:30,239 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 03:45:30,239 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 03:45:30,239 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 03:45:30,239 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 03:45:30,239 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 03:45:30,240 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 03:45:30,240 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 03:45:30,240 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 03:45:30,240 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 03:45:30,240 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 03:45:30,241 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 03:45:30,241 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:45:30,241 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 03:45:30,241 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 03:45:30,241 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 03:45:30,242 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 03:45:30,242 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 03:45:30,242 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 03:45:30,242 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 03:45:30,242 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 03:45:30,243 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 73b8e020dd9d30fdd676c81009d4f1b850aa716d63ef29ce3d475a261546f853 [2022-11-03 03:45:30,506 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 03:45:30,530 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 03:45:30,533 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 03:45:30,534 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 03:45:30,535 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 03:45:30,537 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c [2022-11-03 03:45:30,610 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/data/490c48635/dc5bdd9bcfa44566b965e34556e31e0a/FLAG8202b155c [2022-11-03 03:45:31,139 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 03:45:31,140 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c [2022-11-03 03:45:31,155 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/data/490c48635/dc5bdd9bcfa44566b965e34556e31e0a/FLAG8202b155c [2022-11-03 03:45:31,456 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/data/490c48635/dc5bdd9bcfa44566b965e34556e31e0a [2022-11-03 03:45:31,459 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 03:45:31,460 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 03:45:31,463 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 03:45:31,464 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 03:45:31,467 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 03:45:31,468 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:31,471 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@23174ff2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31, skipping insertion in model container [2022-11-03 03:45:31,471 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:31,479 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 03:45:31,514 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 03:45:31,850 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c[15211,15224] [2022-11-03 03:45:31,870 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:45:31,879 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 03:45:31,933 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/sv-benchmarks/c/product-lines/minepump_spec5_product46.cil.c[15211,15224] [2022-11-03 03:45:31,945 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:45:31,962 INFO L208 MainTranslator]: Completed translation [2022-11-03 03:45:31,963 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31 WrapperNode [2022-11-03 03:45:31,963 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 03:45:31,964 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 03:45:31,964 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 03:45:31,965 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 03:45:31,972 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:31,985 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,012 INFO L138 Inliner]: procedures = 57, calls = 159, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 267 [2022-11-03 03:45:32,012 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 03:45:32,013 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 03:45:32,013 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 03:45:32,013 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 03:45:32,022 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,023 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,025 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,025 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,030 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,035 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,036 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,038 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,041 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 03:45:32,042 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 03:45:32,042 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 03:45:32,042 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 03:45:32,043 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (1/1) ... [2022-11-03 03:45:32,049 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:45:32,061 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:45:32,074 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 03:45:32,105 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 03:45:32,122 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 03:45:32,122 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 03:45:32,122 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 03:45:32,122 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 03:45:32,123 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 03:45:32,123 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 03:45:32,123 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 03:45:32,123 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 03:45:32,123 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 03:45:32,124 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2022-11-03 03:45:32,124 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2022-11-03 03:45:32,124 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-03 03:45:32,124 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-03 03:45:32,124 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2022-11-03 03:45:32,124 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2022-11-03 03:45:32,125 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 03:45:32,125 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 03:45:32,125 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 03:45:32,125 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 03:45:32,125 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 03:45:32,229 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 03:45:32,231 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 03:45:32,635 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 03:45:32,790 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 03:45:32,790 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 03:45:32,793 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:32 BoogieIcfgContainer [2022-11-03 03:45:32,793 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 03:45:32,795 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 03:45:32,796 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 03:45:32,799 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 03:45:32,800 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 03:45:31" (1/3) ... [2022-11-03 03:45:32,800 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1a53aae4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:45:32, skipping insertion in model container [2022-11-03 03:45:32,801 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:45:31" (2/3) ... [2022-11-03 03:45:32,801 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1a53aae4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:45:32, skipping insertion in model container [2022-11-03 03:45:32,801 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:32" (3/3) ... [2022-11-03 03:45:32,803 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product46.cil.c [2022-11-03 03:45:32,823 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 03:45:32,823 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 03:45:32,877 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 03:45:32,884 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@799b871a, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 03:45:32,884 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 03:45:32,889 INFO L276 IsEmpty]: Start isEmpty. Operand has 64 states, 40 states have (on average 1.4) internal successors, (56), 48 states have internal predecessors, (56), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-03 03:45:32,899 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 03:45:32,899 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:32,900 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:32,901 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:32,906 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:32,907 INFO L85 PathProgramCache]: Analyzing trace with hash 360600848, now seen corresponding path program 1 times [2022-11-03 03:45:32,915 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:32,916 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [248451249] [2022-11-03 03:45:32,916 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:32,917 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:33,102 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:33,189 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:45:33,190 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:33,190 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [248451249] [2022-11-03 03:45:33,191 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [248451249] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:33,191 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:33,191 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 03:45:33,193 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1124219020] [2022-11-03 03:45:33,193 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:33,197 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 03:45:33,197 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:33,224 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 03:45:33,225 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:45:33,228 INFO L87 Difference]: Start difference. First operand has 64 states, 40 states have (on average 1.4) internal successors, (56), 48 states have internal predecessors, (56), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:33,342 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:33,342 INFO L93 Difference]: Finished difference Result 126 states and 169 transitions. [2022-11-03 03:45:33,343 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 03:45:33,345 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-03 03:45:33,345 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:33,354 INFO L225 Difference]: With dead ends: 126 [2022-11-03 03:45:33,354 INFO L226 Difference]: Without dead ends: 59 [2022-11-03 03:45:33,357 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:45:33,361 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 64 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:33,362 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 64 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:45:33,379 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 59 states. [2022-11-03 03:45:33,399 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 59 to 59. [2022-11-03 03:45:33,401 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 59 states, 37 states have (on average 1.2972972972972974) internal successors, (48), 44 states have internal predecessors, (48), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 11 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-03 03:45:33,403 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 59 states to 59 states and 75 transitions. [2022-11-03 03:45:33,404 INFO L78 Accepts]: Start accepts. Automaton has 59 states and 75 transitions. Word has length 21 [2022-11-03 03:45:33,405 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:33,405 INFO L495 AbstractCegarLoop]: Abstraction has 59 states and 75 transitions. [2022-11-03 03:45:33,405 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:33,405 INFO L276 IsEmpty]: Start isEmpty. Operand 59 states and 75 transitions. [2022-11-03 03:45:33,407 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-03 03:45:33,407 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:33,408 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:33,408 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 03:45:33,408 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:33,409 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:33,409 INFO L85 PathProgramCache]: Analyzing trace with hash -1869551212, now seen corresponding path program 1 times [2022-11-03 03:45:33,409 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:33,409 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2047210851] [2022-11-03 03:45:33,410 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:33,410 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:33,458 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:33,783 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 03:45:33,783 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:33,784 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2047210851] [2022-11-03 03:45:33,784 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2047210851] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:33,784 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:33,784 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:45:33,784 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [747075061] [2022-11-03 03:45:33,785 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:33,787 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:45:33,788 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:33,789 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:45:33,793 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:45:33,793 INFO L87 Difference]: Start difference. First operand 59 states and 75 transitions. Second operand has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:34,019 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:34,020 INFO L93 Difference]: Finished difference Result 164 states and 229 transitions. [2022-11-03 03:45:34,020 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 03:45:34,020 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 24 [2022-11-03 03:45:34,021 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:34,023 INFO L225 Difference]: With dead ends: 164 [2022-11-03 03:45:34,023 INFO L226 Difference]: Without dead ends: 107 [2022-11-03 03:45:34,024 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 03:45:34,026 INFO L413 NwaCegarLoop]: 81 mSDtfsCounter, 47 mSDsluCounter, 301 mSDsCounter, 0 mSdLazyCounter, 130 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 48 SdHoareTripleChecker+Valid, 340 SdHoareTripleChecker+Invalid, 137 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 130 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:34,026 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [48 Valid, 340 Invalid, 137 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 130 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 03:45:34,027 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 107 states. [2022-11-03 03:45:34,048 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 107 to 103. [2022-11-03 03:45:34,055 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 103 states, 66 states have (on average 1.2424242424242424) internal successors, (82), 73 states have internal predecessors, (82), 22 states have call successors, (22), 16 states have call predecessors, (22), 14 states have return successors, (28), 20 states have call predecessors, (28), 20 states have call successors, (28) [2022-11-03 03:45:34,058 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 103 states to 103 states and 132 transitions. [2022-11-03 03:45:34,061 INFO L78 Accepts]: Start accepts. Automaton has 103 states and 132 transitions. Word has length 24 [2022-11-03 03:45:34,062 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:34,062 INFO L495 AbstractCegarLoop]: Abstraction has 103 states and 132 transitions. [2022-11-03 03:45:34,062 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:45:34,063 INFO L276 IsEmpty]: Start isEmpty. Operand 103 states and 132 transitions. [2022-11-03 03:45:34,065 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-03 03:45:34,066 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:34,066 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:34,066 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 03:45:34,066 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:34,067 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:34,067 INFO L85 PathProgramCache]: Analyzing trace with hash 1883380402, now seen corresponding path program 1 times [2022-11-03 03:45:34,067 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:34,068 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [82450147] [2022-11-03 03:45:34,068 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:34,069 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:34,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:34,587 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:45:34,588 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:34,588 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [82450147] [2022-11-03 03:45:34,588 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [82450147] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:34,589 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:34,589 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-03 03:45:34,589 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2080714724] [2022-11-03 03:45:34,590 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:34,591 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-03 03:45:34,591 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:34,592 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-03 03:45:34,592 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-03 03:45:34,592 INFO L87 Difference]: Start difference. First operand 103 states and 132 transitions. Second operand has 7 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:45:34,888 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:34,889 INFO L93 Difference]: Finished difference Result 300 states and 391 transitions. [2022-11-03 03:45:34,889 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-03 03:45:34,889 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 36 [2022-11-03 03:45:34,890 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:34,892 INFO L225 Difference]: With dead ends: 300 [2022-11-03 03:45:34,892 INFO L226 Difference]: Without dead ends: 191 [2022-11-03 03:45:34,894 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=20, Invalid=36, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:45:34,895 INFO L413 NwaCegarLoop]: 108 mSDtfsCounter, 129 mSDsluCounter, 206 mSDsCounter, 0 mSdLazyCounter, 174 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 131 SdHoareTripleChecker+Valid, 285 SdHoareTripleChecker+Invalid, 206 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 174 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:34,896 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [131 Valid, 285 Invalid, 206 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 174 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 03:45:34,897 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 191 states. [2022-11-03 03:45:34,928 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 191 to 187. [2022-11-03 03:45:34,929 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 187 states, 119 states have (on average 1.226890756302521) internal successors, (146), 131 states have internal predecessors, (146), 40 states have call successors, (40), 30 states have call predecessors, (40), 27 states have return successors, (56), 35 states have call predecessors, (56), 37 states have call successors, (56) [2022-11-03 03:45:34,932 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 187 states to 187 states and 242 transitions. [2022-11-03 03:45:34,933 INFO L78 Accepts]: Start accepts. Automaton has 187 states and 242 transitions. Word has length 36 [2022-11-03 03:45:34,933 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:34,933 INFO L495 AbstractCegarLoop]: Abstraction has 187 states and 242 transitions. [2022-11-03 03:45:34,934 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:45:34,934 INFO L276 IsEmpty]: Start isEmpty. Operand 187 states and 242 transitions. [2022-11-03 03:45:34,936 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2022-11-03 03:45:34,936 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:34,936 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:34,936 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 03:45:34,937 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:34,937 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:34,937 INFO L85 PathProgramCache]: Analyzing trace with hash -532747675, now seen corresponding path program 1 times [2022-11-03 03:45:34,938 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:34,938 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1063989961] [2022-11-03 03:45:34,938 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:34,938 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:34,964 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:35,243 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:45:35,243 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:35,244 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1063989961] [2022-11-03 03:45:35,244 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1063989961] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:35,244 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:35,244 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 03:45:35,245 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [508405507] [2022-11-03 03:45:35,245 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:35,245 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 03:45:35,245 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:35,246 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 03:45:35,246 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:45:35,246 INFO L87 Difference]: Start difference. First operand 187 states and 242 transitions. Second operand has 8 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-03 03:45:35,808 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:35,808 INFO L93 Difference]: Finished difference Result 479 states and 686 transitions. [2022-11-03 03:45:35,809 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 03:45:35,809 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) Word has length 39 [2022-11-03 03:45:35,809 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:35,820 INFO L225 Difference]: With dead ends: 479 [2022-11-03 03:45:35,820 INFO L226 Difference]: Without dead ends: 342 [2022-11-03 03:45:35,821 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-03 03:45:35,831 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 266 mSDsluCounter, 229 mSDsCounter, 0 mSdLazyCounter, 305 mSolverCounterSat, 158 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 272 SdHoareTripleChecker+Valid, 285 SdHoareTripleChecker+Invalid, 463 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 158 IncrementalHoareTripleChecker+Valid, 305 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:35,831 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [272 Valid, 285 Invalid, 463 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [158 Valid, 305 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-03 03:45:35,832 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 342 states. [2022-11-03 03:45:35,892 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 342 to 285. [2022-11-03 03:45:35,893 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 186 states have (on average 1.2365591397849462) internal successors, (230), 203 states have internal predecessors, (230), 59 states have call successors, (59), 39 states have call predecessors, (59), 39 states have return successors, (85), 56 states have call predecessors, (85), 54 states have call successors, (85) [2022-11-03 03:45:35,896 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 374 transitions. [2022-11-03 03:45:35,896 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 374 transitions. Word has length 39 [2022-11-03 03:45:35,896 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:35,897 INFO L495 AbstractCegarLoop]: Abstraction has 285 states and 374 transitions. [2022-11-03 03:45:35,897 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-03 03:45:35,897 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 374 transitions. [2022-11-03 03:45:35,899 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2022-11-03 03:45:35,899 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:35,899 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:35,900 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 03:45:35,900 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:35,900 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:35,901 INFO L85 PathProgramCache]: Analyzing trace with hash -1351785767, now seen corresponding path program 1 times [2022-11-03 03:45:35,901 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:35,901 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [45329417] [2022-11-03 03:45:35,901 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:35,901 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:35,919 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:35,963 INFO L134 CoverageAnalysis]: Checked inductivity of 14 backedges. 6 proven. 0 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-03 03:45:35,963 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:35,963 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [45329417] [2022-11-03 03:45:35,964 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [45329417] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:35,964 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:35,964 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:45:35,964 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [658317524] [2022-11-03 03:45:35,964 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:35,965 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:45:35,965 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:35,966 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:45:35,966 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:45:35,966 INFO L87 Difference]: Start difference. First operand 285 states and 374 transitions. Second operand has 3 states, 3 states have (on average 11.666666666666666) internal successors, (35), 3 states have internal predecessors, (35), 3 states have call successors, (9), 2 states have call predecessors, (9), 1 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:45:36,021 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:36,021 INFO L93 Difference]: Finished difference Result 429 states and 548 transitions. [2022-11-03 03:45:36,021 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:45:36,027 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 11.666666666666666) internal successors, (35), 3 states have internal predecessors, (35), 3 states have call successors, (9), 2 states have call predecessors, (9), 1 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 54 [2022-11-03 03:45:36,028 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:36,029 INFO L225 Difference]: With dead ends: 429 [2022-11-03 03:45:36,029 INFO L226 Difference]: Without dead ends: 245 [2022-11-03 03:45:36,030 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:45:36,036 INFO L413 NwaCegarLoop]: 50 mSDtfsCounter, 2 mSDsluCounter, 52 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 3 SdHoareTripleChecker+Valid, 91 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:36,037 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [3 Valid, 91 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:45:36,038 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 245 states. [2022-11-03 03:45:36,078 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 245 to 245. [2022-11-03 03:45:36,079 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 245 states, 161 states have (on average 1.2422360248447204) internal successors, (200), 178 states have internal predecessors, (200), 44 states have call successors, (44), 34 states have call predecessors, (44), 39 states have return successors, (59), 46 states have call predecessors, (59), 44 states have call successors, (59) [2022-11-03 03:45:36,082 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 245 states to 245 states and 303 transitions. [2022-11-03 03:45:36,082 INFO L78 Accepts]: Start accepts. Automaton has 245 states and 303 transitions. Word has length 54 [2022-11-03 03:45:36,084 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:36,084 INFO L495 AbstractCegarLoop]: Abstraction has 245 states and 303 transitions. [2022-11-03 03:45:36,084 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 11.666666666666666) internal successors, (35), 3 states have internal predecessors, (35), 3 states have call successors, (9), 2 states have call predecessors, (9), 1 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:45:36,084 INFO L276 IsEmpty]: Start isEmpty. Operand 245 states and 303 transitions. [2022-11-03 03:45:36,087 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2022-11-03 03:45:36,087 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:36,087 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:36,088 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 03:45:36,088 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:36,095 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:36,095 INFO L85 PathProgramCache]: Analyzing trace with hash -1643578224, now seen corresponding path program 1 times [2022-11-03 03:45:36,095 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:36,095 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1961489899] [2022-11-03 03:45:36,095 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:36,095 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:36,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:36,216 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 03:45:36,216 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:36,216 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1961489899] [2022-11-03 03:45:36,217 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1961489899] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:45:36,217 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:45:36,217 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:45:36,217 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1784316855] [2022-11-03 03:45:36,217 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:45:36,218 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:45:36,218 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:36,218 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:45:36,218 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:45:36,218 INFO L87 Difference]: Start difference. First operand 245 states and 303 transitions. Second operand has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:45:36,283 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:36,283 INFO L93 Difference]: Finished difference Result 488 states and 610 transitions. [2022-11-03 03:45:36,283 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:45:36,283 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 56 [2022-11-03 03:45:36,284 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:36,285 INFO L225 Difference]: With dead ends: 488 [2022-11-03 03:45:36,285 INFO L226 Difference]: Without dead ends: 245 [2022-11-03 03:45:36,286 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 03:45:36,287 INFO L413 NwaCegarLoop]: 45 mSDtfsCounter, 50 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 50 SdHoareTripleChecker+Valid, 84 SdHoareTripleChecker+Invalid, 36 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:36,287 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [50 Valid, 84 Invalid, 36 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:45:36,288 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 245 states. [2022-11-03 03:45:36,313 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 245 to 245. [2022-11-03 03:45:36,313 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 245 states, 161 states have (on average 1.2111801242236024) internal successors, (195), 178 states have internal predecessors, (195), 44 states have call successors, (44), 34 states have call predecessors, (44), 39 states have return successors, (59), 46 states have call predecessors, (59), 44 states have call successors, (59) [2022-11-03 03:45:36,315 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 245 states to 245 states and 298 transitions. [2022-11-03 03:45:36,315 INFO L78 Accepts]: Start accepts. Automaton has 245 states and 298 transitions. Word has length 56 [2022-11-03 03:45:36,315 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:36,315 INFO L495 AbstractCegarLoop]: Abstraction has 245 states and 298 transitions. [2022-11-03 03:45:36,316 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 9.75) internal successors, (39), 4 states have internal predecessors, (39), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:45:36,316 INFO L276 IsEmpty]: Start isEmpty. Operand 245 states and 298 transitions. [2022-11-03 03:45:36,317 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 69 [2022-11-03 03:45:36,317 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:36,317 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:36,317 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 03:45:36,318 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:36,318 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:36,318 INFO L85 PathProgramCache]: Analyzing trace with hash 153719726, now seen corresponding path program 1 times [2022-11-03 03:45:36,318 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:36,318 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1847549342] [2022-11-03 03:45:36,318 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:36,319 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:36,335 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:36,556 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 9 proven. 11 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-03 03:45:36,557 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:36,557 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1847549342] [2022-11-03 03:45:36,557 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1847549342] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:45:36,557 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1404305689] [2022-11-03 03:45:36,557 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:36,557 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:45:36,557 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:45:36,571 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:45:36,622 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 03:45:36,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:36,725 INFO L263 TraceCheckSpWp]: Trace formula consists of 476 conjuncts, 22 conjunts are in the unsatisfiable core [2022-11-03 03:45:36,732 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:45:36,895 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 30 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:45:36,895 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:45:37,091 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-11-03 03:45:37,091 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1404305689] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:45:37,091 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [459786885] [2022-11-03 03:45:37,109 INFO L159 IcfgInterpreter]: Started Sifa with 40 locations of interest [2022-11-03 03:45:37,115 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:45:37,120 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:45:37,126 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:45:37,126 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:45:40,576 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 31 for LOIs [2022-11-03 03:45:40,581 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 31 for LOIs [2022-11-03 03:45:40,766 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 54 for LOIs [2022-11-03 03:45:40,781 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 26 for LOIs [2022-11-03 03:45:40,934 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 28 for LOIs [2022-11-03 03:45:40,936 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:45:45,781 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '5374#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 1) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| |timeShift_getWaterLevel_#res#1|) (= ~head~0.offset 0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| ~waterLevel~0) (<= 2 |old(~waterLevel~0)|) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (<= |timeShift_getWaterLevel_~retValue_acc~5#1| 2147483647) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (<= 2 |timeShift_getWaterLevel_~retValue_acc~5#1|) (= |old(~switchedOnBeforeTS~0)| 0))' at error location [2022-11-03 03:45:45,782 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:45:45,782 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:45:45,782 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 14 [2022-11-03 03:45:45,783 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [721554365] [2022-11-03 03:45:45,783 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:45:45,785 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-11-03 03:45:45,785 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:45:45,785 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-11-03 03:45:45,786 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=211, Invalid=1595, Unknown=0, NotChecked=0, Total=1806 [2022-11-03 03:45:45,787 INFO L87 Difference]: Start difference. First operand 245 states and 298 transitions. Second operand has 14 states, 13 states have (on average 6.3076923076923075) internal successors, (82), 13 states have internal predecessors, (82), 5 states have call successors, (18), 4 states have call predecessors, (18), 5 states have return successors, (18), 7 states have call predecessors, (18), 5 states have call successors, (18) [2022-11-03 03:45:48,856 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:45:48,856 INFO L93 Difference]: Finished difference Result 1877 states and 2445 transitions. [2022-11-03 03:45:48,857 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 64 states. [2022-11-03 03:45:48,857 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 13 states have (on average 6.3076923076923075) internal successors, (82), 13 states have internal predecessors, (82), 5 states have call successors, (18), 4 states have call predecessors, (18), 5 states have return successors, (18), 7 states have call predecessors, (18), 5 states have call successors, (18) Word has length 68 [2022-11-03 03:45:48,857 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:45:48,868 INFO L225 Difference]: With dead ends: 1877 [2022-11-03 03:45:48,868 INFO L226 Difference]: Without dead ends: 1634 [2022-11-03 03:45:48,873 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 282 GetRequests, 187 SyntacticMatches, 1 SemanticMatches, 94 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3185 ImplicationChecksByTransitivity, 6.0s TimeCoverageRelationStatistics Valid=790, Invalid=8330, Unknown=0, NotChecked=0, Total=9120 [2022-11-03 03:45:48,873 INFO L413 NwaCegarLoop]: 256 mSDtfsCounter, 744 mSDsluCounter, 1351 mSDsCounter, 0 mSdLazyCounter, 1934 mSolverCounterSat, 742 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 755 SdHoareTripleChecker+Valid, 1413 SdHoareTripleChecker+Invalid, 2676 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 742 IncrementalHoareTripleChecker+Valid, 1934 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.7s IncrementalHoareTripleChecker+Time [2022-11-03 03:45:48,874 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [755 Valid, 1413 Invalid, 2676 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [742 Valid, 1934 Invalid, 0 Unknown, 0 Unchecked, 1.7s Time] [2022-11-03 03:45:48,876 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1634 states. [2022-11-03 03:45:49,017 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1634 to 1249. [2022-11-03 03:45:49,021 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1249 states, 819 states have (on average 1.1587301587301588) internal successors, (949), 889 states have internal predecessors, (949), 218 states have call successors, (218), 190 states have call predecessors, (218), 211 states have return successors, (310), 217 states have call predecessors, (310), 218 states have call successors, (310) [2022-11-03 03:45:49,027 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1249 states to 1249 states and 1477 transitions. [2022-11-03 03:45:49,028 INFO L78 Accepts]: Start accepts. Automaton has 1249 states and 1477 transitions. Word has length 68 [2022-11-03 03:45:49,030 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:45:49,030 INFO L495 AbstractCegarLoop]: Abstraction has 1249 states and 1477 transitions. [2022-11-03 03:45:49,031 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 13 states have (on average 6.3076923076923075) internal successors, (82), 13 states have internal predecessors, (82), 5 states have call successors, (18), 4 states have call predecessors, (18), 5 states have return successors, (18), 7 states have call predecessors, (18), 5 states have call successors, (18) [2022-11-03 03:45:49,031 INFO L276 IsEmpty]: Start isEmpty. Operand 1249 states and 1477 transitions. [2022-11-03 03:45:49,033 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 72 [2022-11-03 03:45:49,033 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:45:49,034 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:45:49,058 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-03 03:45:49,243 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:45:49,243 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:45:49,244 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:45:49,244 INFO L85 PathProgramCache]: Analyzing trace with hash 2014421561, now seen corresponding path program 1 times [2022-11-03 03:45:49,244 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:45:49,244 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2046820798] [2022-11-03 03:45:49,244 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:49,244 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:45:49,264 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:49,582 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 6 proven. 14 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-03 03:45:49,583 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:45:49,583 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2046820798] [2022-11-03 03:45:49,583 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2046820798] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:45:49,583 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1122591381] [2022-11-03 03:45:49,583 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:45:49,584 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:45:49,584 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:45:49,585 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:45:49,611 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 03:45:49,700 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:45:49,703 INFO L263 TraceCheckSpWp]: Trace formula consists of 465 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-03 03:45:49,706 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:45:49,770 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 16 proven. 1 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 03:45:49,771 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:45:49,896 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 7 proven. 1 refuted. 0 times theorem prover too weak. 19 trivial. 0 not checked. [2022-11-03 03:45:49,897 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1122591381] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:45:49,897 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1630283046] [2022-11-03 03:45:49,903 INFO L159 IcfgInterpreter]: Started Sifa with 47 locations of interest [2022-11-03 03:45:49,903 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:45:49,904 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:45:49,904 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:45:49,904 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:45:52,217 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 32 for LOIs [2022-11-03 03:45:52,221 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 48 for LOIs [2022-11-03 03:45:52,795 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 20 for LOIs [2022-11-03 03:45:52,797 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 63 for LOIs [2022-11-03 03:45:53,327 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 48 for LOIs [2022-11-03 03:45:53,336 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 42 for LOIs [2022-11-03 03:45:53,342 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:46:00,432 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '10826#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| |timeShift_getWaterLevel_#res#1|) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |old(~pumpRunning~0)| 2147483647) (= 1 ~systemActive~0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| ~waterLevel~0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483648)) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (<= |timeShift_getWaterLevel_~retValue_acc~5#1| 2147483647) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2147483648)))' at error location [2022-11-03 03:46:00,432 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:46:00,433 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:46:00,433 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 16 [2022-11-03 03:46:00,433 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [109832380] [2022-11-03 03:46:00,433 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:46:00,434 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 16 states [2022-11-03 03:46:00,434 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:46:00,434 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 16 interpolants. [2022-11-03 03:46:00,435 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=298, Invalid=2252, Unknown=0, NotChecked=0, Total=2550 [2022-11-03 03:46:00,436 INFO L87 Difference]: Start difference. First operand 1249 states and 1477 transitions. Second operand has 16 states, 13 states have (on average 5.769230769230769) internal successors, (75), 12 states have internal predecessors, (75), 4 states have call successors, (17), 3 states have call predecessors, (17), 6 states have return successors, (20), 9 states have call predecessors, (20), 4 states have call successors, (20) [2022-11-03 03:46:03,253 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:46:03,253 INFO L93 Difference]: Finished difference Result 3078 states and 3763 transitions. [2022-11-03 03:46:03,254 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 77 states. [2022-11-03 03:46:03,254 INFO L78 Accepts]: Start accepts. Automaton has has 16 states, 13 states have (on average 5.769230769230769) internal successors, (75), 12 states have internal predecessors, (75), 4 states have call successors, (17), 3 states have call predecessors, (17), 6 states have return successors, (20), 9 states have call predecessors, (20), 4 states have call successors, (20) Word has length 71 [2022-11-03 03:46:03,254 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:46:03,266 INFO L225 Difference]: With dead ends: 3078 [2022-11-03 03:46:03,266 INFO L226 Difference]: Without dead ends: 2424 [2022-11-03 03:46:03,272 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 321 GetRequests, 201 SyntacticMatches, 2 SemanticMatches, 118 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5210 ImplicationChecksByTransitivity, 8.4s TimeCoverageRelationStatistics Valid=1110, Invalid=13170, Unknown=0, NotChecked=0, Total=14280 [2022-11-03 03:46:03,273 INFO L413 NwaCegarLoop]: 211 mSDtfsCounter, 707 mSDsluCounter, 1054 mSDsCounter, 0 mSdLazyCounter, 1661 mSolverCounterSat, 638 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 712 SdHoareTripleChecker+Valid, 1011 SdHoareTripleChecker+Invalid, 2299 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 638 IncrementalHoareTripleChecker+Valid, 1661 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.3s IncrementalHoareTripleChecker+Time [2022-11-03 03:46:03,274 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [712 Valid, 1011 Invalid, 2299 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [638 Valid, 1661 Invalid, 0 Unknown, 0 Unchecked, 1.3s Time] [2022-11-03 03:46:03,276 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 2424 states. [2022-11-03 03:46:03,464 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 2424 to 1968. [2022-11-03 03:46:03,468 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1968 states, 1286 states have (on average 1.1539657853810263) internal successors, (1484), 1405 states have internal predecessors, (1484), 347 states have call successors, (347), 301 states have call predecessors, (347), 334 states have return successors, (533), 332 states have call predecessors, (533), 347 states have call successors, (533) [2022-11-03 03:46:03,476 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1968 states to 1968 states and 2364 transitions. [2022-11-03 03:46:03,477 INFO L78 Accepts]: Start accepts. Automaton has 1968 states and 2364 transitions. Word has length 71 [2022-11-03 03:46:03,477 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:46:03,477 INFO L495 AbstractCegarLoop]: Abstraction has 1968 states and 2364 transitions. [2022-11-03 03:46:03,477 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 16 states, 13 states have (on average 5.769230769230769) internal successors, (75), 12 states have internal predecessors, (75), 4 states have call successors, (17), 3 states have call predecessors, (17), 6 states have return successors, (20), 9 states have call predecessors, (20), 4 states have call successors, (20) [2022-11-03 03:46:03,478 INFO L276 IsEmpty]: Start isEmpty. Operand 1968 states and 2364 transitions. [2022-11-03 03:46:03,481 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 98 [2022-11-03 03:46:03,482 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:46:03,482 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:46:03,521 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-03 03:46:03,695 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable7 [2022-11-03 03:46:03,695 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:46:03,696 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:46:03,696 INFO L85 PathProgramCache]: Analyzing trace with hash 50428584, now seen corresponding path program 1 times [2022-11-03 03:46:03,696 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:46:03,696 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [760675435] [2022-11-03 03:46:03,696 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:46:03,696 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:46:03,734 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:46:03,897 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 40 proven. 1 refuted. 0 times theorem prover too weak. 43 trivial. 0 not checked. [2022-11-03 03:46:03,897 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:46:03,897 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [760675435] [2022-11-03 03:46:03,898 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [760675435] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:46:03,898 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [935949771] [2022-11-03 03:46:03,898 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:46:03,898 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:46:03,898 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:46:03,899 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:46:03,923 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 03:46:04,031 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:46:04,034 INFO L263 TraceCheckSpWp]: Trace formula consists of 574 conjuncts, 30 conjunts are in the unsatisfiable core [2022-11-03 03:46:04,038 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:46:04,393 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 61 proven. 15 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-03 03:46:04,393 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:46:04,956 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 51 proven. 5 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-11-03 03:46:04,956 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [935949771] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:46:04,956 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1175221929] [2022-11-03 03:46:04,958 INFO L159 IcfgInterpreter]: Started Sifa with 43 locations of interest [2022-11-03 03:46:04,959 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:46:04,959 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:46:04,959 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:46:04,959 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:46:07,201 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 35 for LOIs [2022-11-03 03:46:07,205 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-03 03:46:07,565 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 41 for LOIs [2022-11-03 03:46:07,570 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 29 for LOIs [2022-11-03 03:46:07,699 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 58 for LOIs [2022-11-03 03:46:07,712 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:46:14,206 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '19509#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 1) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| |timeShift_getWaterLevel_#res#1|) (= ~head~0.offset 0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= |timeShift_getWaterLevel_~retValue_acc~5#1| ~waterLevel~0) (<= 2 |old(~waterLevel~0)|) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (<= |timeShift_getWaterLevel_~retValue_acc~5#1| 2147483647) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (<= 2 |timeShift_getWaterLevel_~retValue_acc~5#1|))' at error location [2022-11-03 03:46:14,206 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:46:14,207 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:46:14,207 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 11, 11] total 24 [2022-11-03 03:46:14,207 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1418472818] [2022-11-03 03:46:14,207 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:46:14,207 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 24 states [2022-11-03 03:46:14,207 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:46:14,208 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 24 interpolants. [2022-11-03 03:46:14,209 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=324, Invalid=2756, Unknown=0, NotChecked=0, Total=3080 [2022-11-03 03:46:14,210 INFO L87 Difference]: Start difference. First operand 1968 states and 2364 transitions. Second operand has 24 states, 23 states have (on average 5.782608695652174) internal successors, (133), 23 states have internal predecessors, (133), 13 states have call successors, (30), 5 states have call predecessors, (30), 10 states have return successors, (29), 14 states have call predecessors, (29), 12 states have call successors, (29) [2022-11-03 03:46:20,097 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:46:20,097 INFO L93 Difference]: Finished difference Result 4637 states and 5701 transitions. [2022-11-03 03:46:20,098 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 94 states. [2022-11-03 03:46:20,098 INFO L78 Accepts]: Start accepts. Automaton has has 24 states, 23 states have (on average 5.782608695652174) internal successors, (133), 23 states have internal predecessors, (133), 13 states have call successors, (30), 5 states have call predecessors, (30), 10 states have return successors, (29), 14 states have call predecessors, (29), 12 states have call successors, (29) Word has length 97 [2022-11-03 03:46:20,098 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:46:20,099 INFO L225 Difference]: With dead ends: 4637 [2022-11-03 03:46:20,100 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 03:46:20,113 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 442 GetRequests, 292 SyntacticMatches, 4 SemanticMatches, 146 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7794 ImplicationChecksByTransitivity, 10.1s TimeCoverageRelationStatistics Valid=2087, Invalid=19669, Unknown=0, NotChecked=0, Total=21756 [2022-11-03 03:46:20,116 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 1185 mSDsluCounter, 852 mSDsCounter, 0 mSdLazyCounter, 2806 mSolverCounterSat, 1170 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1185 SdHoareTripleChecker+Valid, 761 SdHoareTripleChecker+Invalid, 3976 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1170 IncrementalHoareTripleChecker+Valid, 2806 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:46:20,116 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1185 Valid, 761 Invalid, 3976 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1170 Valid, 2806 Invalid, 0 Unknown, 0 Unchecked, 2.1s Time] [2022-11-03 03:46:20,117 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 03:46:20,117 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 03:46:20,117 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 03:46:20,117 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 03:46:20,118 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 97 [2022-11-03 03:46:20,118 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:46:20,118 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 03:46:20,119 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 24 states, 23 states have (on average 5.782608695652174) internal successors, (133), 23 states have internal predecessors, (133), 13 states have call successors, (30), 5 states have call predecessors, (30), 10 states have return successors, (29), 14 states have call predecessors, (29), 12 states have call successors, (29) [2022-11-03 03:46:20,119 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 03:46:20,119 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 03:46:20,121 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 03:46:20,161 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 03:46:20,343 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:46:20,344 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 03:46:46,683 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 748 754) no Hoare annotation was computed. [2022-11-03 03:46:46,684 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 748 754) the Hoare annotation is: true [2022-11-03 03:46:46,685 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 603 614) the Hoare annotation is: (let ((.cse1 (= |old(~methaneLevelCritical~0)| 0)) (.cse7 (= ~methaneLevelCritical~0 0))) (let ((.cse2 (not .cse7)) (.cse5 (not (<= 2 ~waterLevel~0))) (.cse3 (not (<= ~waterLevel~0 2))) (.cse8 (not (= ~waterLevel~0 1))) (.cse10 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse6 (not .cse1)) (.cse0 (not (= ~pumpRunning~0 0))) (.cse9 (not (= 2 ~waterLevel~0))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse1 .cse5 .cse2 .cse3 .cse4) (or .cse6 .cse7 .cse5 (not (= ~pumpRunning~0 1)) .cse3 .cse4) (or .cse8 .cse6 .cse0 .cse7 .cse4) (or .cse6 .cse7 .cse9 .cse10 .cse4) (or .cse6 (not (<= ~waterLevel~0 0)) .cse7 .cse10 .cse4) (or .cse8 .cse6 .cse7 .cse10 .cse4) (or .cse6 .cse0 .cse7 .cse9 .cse4)))) [2022-11-03 03:46:46,685 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 603 614) no Hoare annotation was computed. [2022-11-03 03:46:46,685 INFO L899 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2022-11-03 03:46:46,685 INFO L895 garLoopResultBuilder]: At program point L796(line 796) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse10 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse13 (not (= |old(~waterLevel~0)| 1))) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= ~pumpRunning~0 1)) (.cse11 (= ~methaneLevelCritical~0 0)) (.cse3 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= 0 ~systemActive~0))) (and (or (and .cse0 .cse1 (= ~waterLevel~0 1) .cse2) .cse3 .cse4) (or .cse5 .cse3 .cse4) (or .cse6 .cse4 .cse7 .cse8 (not (<= 2 |old(~waterLevel~0)|))) (or .cse9 .cse10 .cse11 .cse4) (or .cse9 .cse6 .cse4 (not (<= |old(~waterLevel~0)| 0)) .cse8) (or .cse9 (and .cse0 .cse1 (let ((.cse12 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse12) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse12))) .cse2) .cse4 .cse7) (or .cse10 .cse5 .cse4) (or .cse5 .cse13) (or .cse9 .cse13 .cse6 .cse4 .cse8) (or .cse11 .cse3 .cse4))) [2022-11-03 03:46:46,686 INFO L895 garLoopResultBuilder]: At program point L788(line 788) the Hoare annotation is: (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= ~pumpRunning~0 1)) (.cse1 (not (= ~pumpRunning~0 0))) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse10 (not (<= |old(~waterLevel~0)| 1))) (.cse4 (= 0 ~systemActive~0)) (.cse9 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and .cse1 (let ((.cse2 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse2) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2))) .cse3) .cse4 (not (<= |old(~waterLevel~0)| 2))) (or .cse5 .cse6 .cse7 .cse4 .cse8) (or .cse9 .cse7 .cse4) (or .cse0 .cse10 .cse5 .cse6 .cse4 .cse8) (or (and .cse1 (= ~waterLevel~0 1) .cse3) .cse7 .cse4) (or .cse10 .cse9 .cse4) (or .cse9 (not (= |old(~waterLevel~0)| 1))))) [2022-11-03 03:46:46,686 INFO L899 garLoopResultBuilder]: For program point L788-1(line 788) no Hoare annotation was computed. [2022-11-03 03:46:46,687 INFO L895 garLoopResultBuilder]: At program point L82(line 82) the Hoare annotation is: (let ((.cse20 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse10 (not (= |old(~pumpRunning~0)| 1))) (.cse13 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| ~waterLevel~0)) (.cse14 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse16 (let ((.cse21 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse21) .cse20) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse21)))) (.cse4 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~pumpRunning~0 0)) (.cse18 (= ~methaneLevelCritical~0 0))) (let ((.cse8 (= ~pumpRunning~0 1)) (.cse2 (= ~waterLevel~0 1)) (.cse5 (not .cse18)) (.cse11 (not (<= |old(~waterLevel~0)| 2))) (.cse12 (not .cse1)) (.cse9 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse17 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (not .cse4)) (.cse15 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse19 (and (not (= ~switchedOnBeforeTS~0 0)) .cse1 .cse13 .cse14 .cse16)) (.cse3 (and .cse18 .cse10)) (.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse7 (= 0 ~systemActive~0))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse1 .cse2)) (or .cse3 .cse4 .cse5 .cse6 .cse7 .cse8) (or .cse0 .cse6 .cse7) (or .cse9 .cse5 .cse10 .cse7 .cse11 .cse8) (or (and .cse12 .cse13 .cse14 .cse2 .cse15) .cse5 .cse6 .cse7) (or .cse9 .cse4 .cse5 .cse7 .cse11 (and .cse12 .cse13 .cse14 .cse16 .cse15)) (or .cse9 .cse17 .cse18 .cse19 .cse4 .cse7) (or .cse17 .cse0 .cse7 (and .cse1 .cse13 .cse20 .cse15)) (or .cse18 .cse19 .cse3 .cse4 .cse6 .cse7))))) [2022-11-03 03:46:46,687 INFO L899 garLoopResultBuilder]: For program point L82-1(line 82) no Hoare annotation was computed. [2022-11-03 03:46:46,687 INFO L895 garLoopResultBuilder]: At program point L710(line 710) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse0) (or (not (= |old(~waterLevel~0)| 2)) .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2022-11-03 03:46:46,687 INFO L895 garLoopResultBuilder]: At program point L801(line 801) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse0 (= |old(~pumpRunning~0)| 0))) (let ((.cse3 (not .cse0)) (.cse5 (and .cse4 (= |old(~waterLevel~0)| ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and (= ~methaneLevelCritical~0 0) (not (= |old(~pumpRunning~0)| 1))) .cse0 .cse1 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse3 (not (= |old(~waterLevel~0)| 1)) (and .cse4 (= ~waterLevel~0 1))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 .cse1 .cse2) (or .cse5 (not (= |old(~waterLevel~0)| 2)) .cse1) (or .cse3 .cse5 .cse1 .cse2)))) [2022-11-03 03:46:46,688 INFO L895 garLoopResultBuilder]: At program point L801-1(lines 782 806) the Hoare annotation is: (let ((.cse20 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (= 0 ~systemActive~0)) (.cse10 (= ~pumpRunning~0 1)) (.cse16 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse2 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse12 (= ~pumpRunning~0 0)) (.cse15 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse19 (let ((.cse21 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse21) .cse20) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse21))))) (let ((.cse0 (and (not (= ~switchedOnBeforeTS~0 0)) .cse12 .cse15 .cse19)) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse13 (= ~waterLevel~0 1)) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse14 (not .cse12)) (.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse8 (not .cse1)) (.cse9 (not (= |old(~pumpRunning~0)| 1))) (.cse11 (not .cse2)) (.cse17 (and .cse12 .cse20 .cse16)) (.cse18 (and (= 2 ~waterLevel~0) .cse1 .cse20 (not .cse3) .cse10)) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse9 .cse3 .cse10) (or .cse6 .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse11 .cse7 (and .cse12 .cse13)) (or (and .cse14 .cse15 .cse13 .cse16) .cse17 .cse8 (not (= |old(~waterLevel~0)| 2)) .cse18 .cse3) (or (and .cse13 .cse10) .cse8 .cse9 .cse3 .cse4 .cse5) (or .cse6 .cse2 .cse8 (and .cse14 .cse15 .cse19 .cse16) .cse3 .cse4) (or .cse6 .cse8 .cse9 .cse3 (not (<= |old(~waterLevel~0)| 0)) .cse10) (or .cse11 .cse17 .cse18 .cse3 .cse4))))) [2022-11-03 03:46:46,689 INFO L895 garLoopResultBuilder]: At program point L735-1(lines 735 741) the Hoare annotation is: (let ((.cse20 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (= 0 ~systemActive~0)) (.cse10 (= ~pumpRunning~0 1)) (.cse16 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse2 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse12 (= ~pumpRunning~0 0)) (.cse15 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse19 (let ((.cse21 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse21) .cse20) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse21))))) (let ((.cse0 (and (not (= ~switchedOnBeforeTS~0 0)) .cse12 .cse15 .cse19)) (.cse7 (not (= |old(~waterLevel~0)| 1))) (.cse13 (= ~waterLevel~0 1)) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse14 (not .cse12)) (.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse8 (not .cse1)) (.cse9 (not (= |old(~pumpRunning~0)| 1))) (.cse11 (not .cse2)) (.cse17 (and .cse12 .cse20 .cse16)) (.cse18 (and (= 2 ~waterLevel~0) .cse1 .cse20 (not .cse3) .cse10)) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse9 .cse3 .cse10) (or .cse6 .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse11 .cse7 (and .cse12 .cse13)) (or (and .cse14 .cse15 .cse13 .cse16) .cse17 .cse8 (not (= |old(~waterLevel~0)| 2)) .cse18 .cse3) (or (and .cse13 .cse10) .cse8 .cse9 .cse3 .cse4 .cse5) (or .cse6 .cse2 .cse8 (and .cse14 .cse15 .cse19 .cse16) .cse3 .cse4) (or .cse6 .cse8 .cse9 .cse3 (not (<= |old(~waterLevel~0)| 0)) .cse10) (or .cse11 .cse17 .cse18 .cse3 .cse4))))) [2022-11-03 03:46:46,689 INFO L895 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: (let ((.cse6 (= |old(~pumpRunning~0)| 0)) (.cse14 (= ~methaneLevelCritical~0 0)) (.cse12 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= ~pumpRunning~0 0))) (let ((.cse7 (not .cse3)) (.cse9 (and .cse14 .cse12)) (.cse11 (not .cse14)) (.cse13 (= ~pumpRunning~0 1)) (.cse10 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not .cse6)) (.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~switchedOnBeforeTS~0 0)) .cse0 .cse1 .cse2 (= |old(~switchedOnBeforeTS~0)| 0)) (or .cse0 .cse3 .cse4 .cse1) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse3 (= ~waterLevel~0 1))) (or .cse5 .cse6 .cse1 .cse2 (and .cse7 .cse8)) (or .cse7 .cse9 .cse6 .cse1 .cse2 .cse10) (or .cse5 .cse11 .cse12 .cse1 .cse2 .cse13) (or .cse9 .cse11 .cse1 .cse2 .cse13 .cse10) (or .cse5 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or .cse0 (and .cse3 .cse8) .cse1 (not (<= |old(~waterLevel~0)| 0))) (or .cse4 .cse8 .cse1)))) [2022-11-03 03:46:46,690 INFO L895 garLoopResultBuilder]: At program point L67-1(line 67) the Hoare annotation is: (let ((.cse8 (= |old(~pumpRunning~0)| 0)) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse12 (= ~waterLevel~0 1))) (let ((.cse9 (or .cse0 .cse12)) (.cse1 (= |timeShift___utac_acc__Specification5_spec__2_#t~ret4#1| ~pumpRunning~0)) (.cse15 (= ~pumpRunning~0 1)) (.cse19 (= ~methaneLevelCritical~0 0)) (.cse4 (not .cse8))) (let ((.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse10 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse17 (and (or (not (<= |old(~waterLevel~0)| 1)) .cse4) (not (<= |old(~waterLevel~0)| 0)))) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse16 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse11 (not (= |old(~waterLevel~0)| 1))) (.cse13 (not .cse19)) (.cse14 (not (= |old(~pumpRunning~0)| 1))) (.cse18 (and .cse9 .cse1 .cse15)) (.cse3 (= 0 ~systemActive~0))) (and (or (and .cse0 .cse1) .cse2 .cse3) (or .cse4 (and .cse5 .cse0 .cse1) .cse3 .cse6) (or .cse7 .cse8 .cse3 .cse6 (and (not (= |timeShift___utac_acc__Specification5_spec__2_#t~ret4#1| 0)) .cse9 .cse10 .cse1)) (or .cse4 .cse11 (and .cse5 .cse12)) (or .cse13 .cse14 .cse3 .cse6 .cse15 .cse16) (or .cse7 .cse5 .cse17 (<= ~waterLevel~0 0) .cse3) (or .cse7 .cse2 .cse3 .cse10) (or .cse7 .cse11 .cse3 .cse10) (or .cse7 .cse17 .cse13 .cse14 .cse18 .cse3) (or (not .cse5) .cse19 .cse8 .cse3 .cse6 .cse16) (or .cse7 .cse11 .cse13 .cse14 .cse18 .cse3))))) [2022-11-03 03:46:46,690 INFO L899 garLoopResultBuilder]: For program point L728-2(lines 724 746) no Hoare annotation was computed. [2022-11-03 03:46:46,690 INFO L895 garLoopResultBuilder]: At program point L790(lines 790 798) the Hoare annotation is: (let ((.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (= ~pumpRunning~0 1)) (.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= |old(~waterLevel~0)| 1))) (.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse11 (not (<= |old(~waterLevel~0)| 1))) (.cse6 (not (= ~pumpRunning~0 0))) (.cse7 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse8 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or (and .cse6 .cse7 (= ~waterLevel~0 1) .cse8) .cse9 .cse4) (or .cse2 .cse3 .cse4 (not (<= |old(~waterLevel~0)| 2)) .cse5 (not (<= 2 |old(~waterLevel~0)|))) (or .cse10 .cse9 .cse4) (or .cse0 .cse2 .cse3 .cse4 (not (<= |old(~waterLevel~0)| 0)) .cse5) (or .cse11 .cse10 .cse4) (or .cse10 .cse1) (or .cse0 .cse11 (and .cse6 .cse7 (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse8) .cse4))) [2022-11-03 03:46:46,690 INFO L899 garLoopResultBuilder]: For program point L84(lines 84 94) no Hoare annotation was computed. [2022-11-03 03:46:46,690 INFO L899 garLoopResultBuilder]: For program point L786(lines 786 803) no Hoare annotation was computed. [2022-11-03 03:46:46,691 INFO L899 garLoopResultBuilder]: For program point L80(lines 80 97) no Hoare annotation was computed. [2022-11-03 03:46:46,691 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 721 747) the Hoare annotation is: (let ((.cse6 (= |old(~pumpRunning~0)| 0)) (.cse14 (= ~methaneLevelCritical~0 0)) (.cse12 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= ~pumpRunning~0 0))) (let ((.cse7 (not .cse3)) (.cse9 (and .cse14 .cse12)) (.cse11 (not .cse14)) (.cse13 (= ~pumpRunning~0 1)) (.cse10 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not .cse6)) (.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~switchedOnBeforeTS~0 0)) .cse0 .cse1 .cse2 (= |old(~switchedOnBeforeTS~0)| 0)) (or .cse0 .cse3 .cse4 .cse1) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse3 (= ~waterLevel~0 1))) (or .cse5 .cse6 .cse1 .cse2 (and .cse7 .cse8)) (or .cse7 .cse9 .cse6 .cse1 .cse2 .cse10) (or .cse5 .cse11 .cse12 .cse1 .cse2 .cse13) (or .cse9 .cse11 .cse1 .cse2 .cse13 .cse10) (or .cse5 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or .cse0 (and .cse3 .cse8) .cse1 (not (<= |old(~waterLevel~0)| 0))) (or .cse4 .cse8 .cse1)))) [2022-11-03 03:46:46,692 INFO L895 garLoopResultBuilder]: At program point L80-1(lines 72 100) the Hoare annotation is: (let ((.cse7 (= ~methaneLevelCritical~0 0)) (.cse24 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~pumpRunning~0 0)) (.cse19 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse13 (= ~waterLevel~0 1))) (let ((.cse6 (or .cse19 .cse13)) (.cse14 (not .cse1)) (.cse0 (not (= ~switchedOnBeforeTS~0 0))) (.cse4 (= |timeShift_processEnvironment_~tmp~6#1| ~methaneLevelCritical~0)) (.cse5 (let ((.cse25 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse25) .cse19) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse25)))) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse11 (not (<= 2 |old(~waterLevel~0)|))) (.cse23 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| ~waterLevel~0)) (.cse15 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse12 (not .cse8)) (.cse17 (not (= |old(~waterLevel~0)| 2))) (.cse18 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (.cse22 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse3 (not (= |old(~waterLevel~0)| 1))) (.cse21 (and .cse7 .cse24)) (.cse16 (not .cse7)) (.cse9 (= 0 ~systemActive~0)) (.cse20 (= ~pumpRunning~0 1))) (and (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) .cse7 .cse8 .cse9 .cse10 .cse11) (or .cse12 .cse3 (and .cse1 .cse13)) (or (and .cse14 .cse2 .cse4 .cse13 .cse15) .cse16 .cse17 .cse9 (and .cse1 (= 2 ~waterLevel~0) .cse3 .cse6 .cse15 .cse18) (and .cse19 .cse20 .cse18)) (or .cse12 (and .cse1 .cse19 .cse15) .cse21 .cse17 .cse9) (or .cse22 .cse8 .cse16 .cse9 .cse10 (and .cse14 .cse2 .cse4 .cse5 .cse15)) (or .cse22 .cse23 .cse7 (and .cse0 .cse1 .cse2 .cse4 .cse5) .cse8 .cse9) (or (and .cse13 .cse20) .cse16 .cse24 .cse9 .cse10 .cse11) (or .cse22 .cse16 .cse24 .cse9 (not (<= |old(~waterLevel~0)| 0)) .cse20) (or .cse23 .cse12 .cse9 (and .cse1 .cse2 .cse19 .cse15)) (or .cse12 .cse17 .cse9 .cse18) (or .cse22 .cse3 .cse21 .cse16 .cse9 .cse20)))) [2022-11-03 03:46:46,692 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 721 747) no Hoare annotation was computed. [2022-11-03 03:46:46,692 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 710) no Hoare annotation was computed. [2022-11-03 03:46:46,692 INFO L902 garLoopResultBuilder]: At program point L129(lines 104 133) the Hoare annotation is: true [2022-11-03 03:46:46,692 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 104 133) no Hoare annotation was computed. [2022-11-03 03:46:46,692 INFO L899 garLoopResultBuilder]: For program point L125(line 125) no Hoare annotation was computed. [2022-11-03 03:46:46,693 INFO L895 garLoopResultBuilder]: At program point cleanupENTRY(lines 104 133) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))) [2022-11-03 03:46:46,693 INFO L899 garLoopResultBuilder]: For program point L118(lines 118 122) no Hoare annotation was computed. [2022-11-03 03:46:46,693 INFO L895 garLoopResultBuilder]: At program point L118-1(lines 118 122) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))) [2022-11-03 03:46:46,693 INFO L895 garLoopResultBuilder]: At program point L114-2(lines 114 128) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))) [2022-11-03 03:46:46,693 INFO L895 garLoopResultBuilder]: At program point L110(line 110) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))) [2022-11-03 03:46:46,694 INFO L899 garLoopResultBuilder]: For program point L110-1(line 110) no Hoare annotation was computed. [2022-11-03 03:46:46,694 INFO L895 garLoopResultBuilder]: At program point L956(line 956) the Hoare annotation is: (let ((.cse6 (= ~methaneLevelCritical~0 0))) (let ((.cse4 (not .cse6)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3) (and .cse0 .cse4 .cse1 .cse5 .cse2 .cse3) (and (= 2 ~waterLevel~0) (or .cse4 (= ~pumpRunning~0 1)) .cse1 .cse2 .cse3) (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse5 .cse2 .cse3) (and .cse6 .cse1 .cse5 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse3)))) [2022-11-03 03:46:46,694 INFO L902 garLoopResultBuilder]: At program point L985(lines 924 989) the Hoare annotation is: true [2022-11-03 03:46:46,694 INFO L899 garLoopResultBuilder]: For program point L944(lines 944 950) no Hoare annotation was computed. [2022-11-03 03:46:46,694 INFO L899 garLoopResultBuilder]: For program point L944-1(lines 944 950) no Hoare annotation was computed. [2022-11-03 03:46:46,694 INFO L895 garLoopResultBuilder]: At program point L193(lines 193 200) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_main_~tmp~1#1| 1) (= ~waterLevel~0 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= 0 ~systemActive~0))) [2022-11-03 03:46:46,695 INFO L902 garLoopResultBuilder]: At program point L193-2(lines 193 200) the Hoare annotation is: true [2022-11-03 03:46:46,695 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 03:46:46,695 INFO L895 garLoopResultBuilder]: At program point L982(lines 933 983) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~1#1| 1) (= ~waterLevel~0 1)) [2022-11-03 03:46:46,695 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 03:46:46,695 INFO L899 garLoopResultBuilder]: For program point L954(lines 954 960) no Hoare annotation was computed. [2022-11-03 03:46:46,695 INFO L895 garLoopResultBuilder]: At program point L954-1(lines 954 960) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= ~waterLevel~0 2) .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 .cse1 .cse2) (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2))) [2022-11-03 03:46:46,696 INFO L895 garLoopResultBuilder]: At program point L979(lines 934 981) the Hoare annotation is: (let ((.cse5 (= ~methaneLevelCritical~0 0))) (let ((.cse7 (= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (not .cse5)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (= ~waterLevel~0 1)) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse5 .cse1 (<= ~waterLevel~0 0) .cse2 .cse6 .cse4) (and .cse7 (or .cse8 (= ~pumpRunning~0 1)) .cse1 .cse2 .cse4) (and .cse0 .cse7 .cse1 .cse2 .cse4) (and .cse0 (<= ~waterLevel~0 1) .cse8 .cse1 .cse2 .cse4) (and .cse5 .cse1 .cse2 .cse3 .cse6 .cse4)))) [2022-11-03 03:46:46,696 INFO L895 garLoopResultBuilder]: At program point L946(line 946) the Hoare annotation is: (let ((.cse5 (= ~methaneLevelCritical~0 0))) (let ((.cse6 (= ~pumpRunning~0 1)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (not .cse5)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse1 (= ~waterLevel~0 1)) (.cse7 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and (or (and .cse0 .cse1) (and .cse0 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) .cse2 .cse3 .cse4) (and .cse5 .cse2 .cse3 .cse1 .cse4 .cse6) (and .cse5 .cse2 (<= ~waterLevel~0 0) .cse3 .cse7 .cse4) (and (= 2 ~waterLevel~0) (or .cse8 .cse6) .cse2 .cse3 .cse4) (and .cse0 (<= ~waterLevel~0 1) .cse8 .cse2 .cse3 .cse4) (and .cse5 .cse2 .cse3 .cse1 .cse7 .cse4)))) [2022-11-03 03:46:46,696 INFO L895 garLoopResultBuilder]: At program point L972-2(lines 964 977) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= ~waterLevel~0 2) .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 .cse1 .cse2) (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2))) [2022-11-03 03:46:46,696 INFO L899 garLoopResultBuilder]: For program point L935(lines 934 981) no Hoare annotation was computed. [2022-11-03 03:46:46,697 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 591 602) no Hoare annotation was computed. [2022-11-03 03:46:46,697 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 591 602) the Hoare annotation is: (let ((.cse1 (= ~methaneLevelCritical~0 0)) (.cse0 (not (= ~pumpRunning~0 0)))) (let ((.cse2 (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0) (not (<= |old(~waterLevel~0)| 0)))) (.cse8 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (not (= |old(~waterLevel~0)| 1))) (.cse7 (not .cse1)) (.cse5 (not (= ~pumpRunning~0 1))) (.cse4 (= 0 ~systemActive~0)) (.cse9 (= ~waterLevel~0 1))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or (= 2 ~waterLevel~0) (and .cse1 .cse5) .cse4 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse6 .cse7 .cse8 .cse4 .cse9) (or .cse2 .cse7 .cse8 .cse3 .cse4) (or .cse0 (not (= |old(~waterLevel~0)| 2)) .cse3 .cse4) (or .cse0 .cse6 .cse3 .cse4) (or .cse6 .cse7 .cse5 .cse4 .cse9)))) [2022-11-03 03:46:46,697 INFO L899 garLoopResultBuilder]: For program point L764(lines 764 772) no Hoare annotation was computed. [2022-11-03 03:46:46,697 INFO L895 garLoopResultBuilder]: At program point L760(lines 760 777) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 .cse1 .cse2))) [2022-11-03 03:46:46,697 INFO L895 garLoopResultBuilder]: At program point L820(line 820) the Hoare annotation is: (let ((.cse0 (= |old(~pumpRunning~0)| 0)) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not .cse0) (and (= 2 ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1 .cse2 .cse3) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2 .cse3))) [2022-11-03 03:46:46,698 INFO L895 garLoopResultBuilder]: At program point L820-1(line 820) the Hoare annotation is: (let ((.cse4 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse4)) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 .cse2 .cse3) (or .cse4 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2 .cse3) (or .cse0 (and (= |processEnvironment__wrappee__methaneQuery_activatePump_#t~ret39#1| ~methaneLevelCritical~0) (<= 2 ~waterLevel~0)) .cse1 .cse2 .cse3)))) [2022-11-03 03:46:46,698 INFO L895 garLoopResultBuilder]: At program point L775(line 775) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1 .cse2))) [2022-11-03 03:46:46,698 INFO L899 garLoopResultBuilder]: For program point L775-1(lines 756 780) no Hoare annotation was computed. [2022-11-03 03:46:46,698 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 756 780) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 .cse1 .cse2))) [2022-11-03 03:46:46,698 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 756 780) no Hoare annotation was computed. [2022-11-03 03:46:46,699 INFO L895 garLoopResultBuilder]: At program point L770(line 770) the Hoare annotation is: (let ((.cse0 (= |old(~pumpRunning~0)| 0)) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not .cse0) (and (or (= |processEnvironment__wrappee__methaneQuery_~tmp~5#1| 0) (not (<= ~waterLevel~0 1))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1 .cse2 .cse3) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2 .cse3))) [2022-11-03 03:46:46,699 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 851 859) no Hoare annotation was computed. [2022-11-03 03:46:46,699 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 851 859) the Hoare annotation is: true [2022-11-03 03:46:46,699 INFO L902 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 840 850) the Hoare annotation is: true [2022-11-03 03:46:46,699 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 840 850) no Hoare annotation was computed. [2022-11-03 03:46:46,703 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:46:46,705 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 03:46:46,746 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 03:46:46 BoogieIcfgContainer [2022-11-03 03:46:46,746 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 03:46:46,747 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 03:46:46,747 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 03:46:46,747 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 03:46:46,748 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:45:32" (3/4) ... [2022-11-03 03:46:46,751 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 03:46:46,758 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 03:46:46,759 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 03:46:46,759 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 03:46:46,759 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 03:46:46,759 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 03:46:46,759 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2022-11-03 03:46:46,760 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-03 03:46:46,760 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2022-11-03 03:46:46,767 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 78 nodes and edges [2022-11-03 03:46:46,768 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 27 nodes and edges [2022-11-03 03:46:46,768 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 13 nodes and edges [2022-11-03 03:46:46,769 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 03:46:46,769 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 03:46:46,769 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:46:46,770 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:46:46,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1) [2022-11-03 03:46:46,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((\old(waterLevel) == waterLevel && aux-isPumpRunning()-aux == pumpRunning) || !(\old(waterLevel) == 2)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(aux-isPumpRunning()-aux == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && pumpRunning == switchedOnBeforeTS) && aux-isPumpRunning()-aux == pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && (((((!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || pumpRunning == 0) || ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && !(\old(waterLevel) <= 0))) || waterLevel <= 0) || 0 == systemActive)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && !(\old(waterLevel) <= 0))) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((\old(waterLevel) == waterLevel || waterLevel == 1) && aux-isPumpRunning()-aux == pumpRunning) && pumpRunning == 1)) || 0 == systemActive)) && (((((!(pumpRunning == 0) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((\old(waterLevel) == waterLevel || waterLevel == 1) && aux-isPumpRunning()-aux == pumpRunning) && pumpRunning == 1)) || 0 == systemActive) [2022-11-03 03:46:46,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && ((((((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (((!(pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-03 03:46:46,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && !(\old(waterLevel) == 1)) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && (\old(waterLevel) == waterLevel || waterLevel == 1)) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && (((((((((!(pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || (((((pumpRunning == 0 && 2 == waterLevel) && !(\old(waterLevel) == 1)) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && pumpRunning == switchedOnBeforeTS) && tmp == 2)) || ((\old(waterLevel) == waterLevel && pumpRunning == 1) && tmp == 2))) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || (methaneLevelCritical == 0 && !(\old(pumpRunning) == 1))) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((!(pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || methaneLevelCritical == 0) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(pumpRunning) == 0) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 2)) || 0 == systemActive) || tmp == 2)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || (methaneLevelCritical == 0 && !(\old(pumpRunning) == 1))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || pumpRunning == 1) [2022-11-03 03:46:46,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive)) && (!(\old(waterLevel) == 2) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) [2022-11-03 03:46:46,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && ((((((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (((!(pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-03 03:46:46,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(methaneLevelCritical == 0) || !(waterLevel <= 2)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-03 03:46:46,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1) && (((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || ((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) [2022-11-03 03:46:46,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((\old(pumpRunning) == 0 || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || (aux-isMethaneAlarm()-aux == methaneLevelCritical && 2 <= waterLevel)) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-03 03:46:46,823 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 03:46:46,824 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 03:46:46,824 INFO L158 Benchmark]: Toolchain (without parser) took 75364.11ms. Allocated memory was 94.4MB in the beginning and 599.8MB in the end (delta: 505.4MB). Free memory was 49.2MB in the beginning and 435.4MB in the end (delta: -386.2MB). Peak memory consumption was 117.2MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,825 INFO L158 Benchmark]: CDTParser took 0.27ms. Allocated memory is still 94.4MB. Free memory is still 66.2MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:46:46,825 INFO L158 Benchmark]: CACSL2BoogieTranslator took 500.05ms. Allocated memory is still 94.4MB. Free memory was 48.9MB in the beginning and 59.6MB in the end (delta: -10.7MB). Peak memory consumption was 6.5MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,825 INFO L158 Benchmark]: Boogie Procedure Inliner took 48.33ms. Allocated memory is still 94.4MB. Free memory was 59.6MB in the beginning and 56.8MB in the end (delta: 2.7MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,826 INFO L158 Benchmark]: Boogie Preprocessor took 27.92ms. Allocated memory is still 94.4MB. Free memory was 56.8MB in the beginning and 55.4MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:46:46,826 INFO L158 Benchmark]: RCFGBuilder took 751.76ms. Allocated memory was 94.4MB in the beginning and 113.2MB in the end (delta: 18.9MB). Free memory was 55.0MB in the beginning and 81.6MB in the end (delta: -26.5MB). Peak memory consumption was 29.0MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,826 INFO L158 Benchmark]: TraceAbstraction took 73950.92ms. Allocated memory was 113.2MB in the beginning and 599.8MB in the end (delta: 486.5MB). Free memory was 80.9MB in the beginning and 441.7MB in the end (delta: -360.8MB). Peak memory consumption was 366.9MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,827 INFO L158 Benchmark]: Witness Printer took 76.99ms. Allocated memory is still 599.8MB. Free memory was 441.7MB in the beginning and 435.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-03 03:46:46,828 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.27ms. Allocated memory is still 94.4MB. Free memory is still 66.2MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 500.05ms. Allocated memory is still 94.4MB. Free memory was 48.9MB in the beginning and 59.6MB in the end (delta: -10.7MB). Peak memory consumption was 6.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 48.33ms. Allocated memory is still 94.4MB. Free memory was 59.6MB in the beginning and 56.8MB in the end (delta: 2.7MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 27.92ms. Allocated memory is still 94.4MB. Free memory was 56.8MB in the beginning and 55.4MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 751.76ms. Allocated memory was 94.4MB in the beginning and 113.2MB in the end (delta: 18.9MB). Free memory was 55.0MB in the beginning and 81.6MB in the end (delta: -26.5MB). Peak memory consumption was 29.0MB. Max. memory is 16.1GB. * TraceAbstraction took 73950.92ms. Allocated memory was 113.2MB in the beginning and 599.8MB in the end (delta: 486.5MB). Free memory was 80.9MB in the beginning and 441.7MB in the end (delta: -360.8MB). Peak memory consumption was 366.9MB. Max. memory is 16.1GB. * Witness Printer took 76.99ms. Allocated memory is still 599.8MB. Free memory was 441.7MB in the beginning and 435.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 710]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 64 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 73.8s, OverallIterations: 9, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 13.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 26.3s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3156 SdHoareTripleChecker+Valid, 5.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3130 mSDsluCounter, 4334 SdHoareTripleChecker+Invalid, 4.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 4094 mSDsCounter, 2755 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 7081 IncrementalHoareTripleChecker+Invalid, 9836 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 2755 mSolverCounterUnsat, 1021 mSDtfsCounter, 7081 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1096 GetRequests, 701 SyntacticMatches, 7 SemanticMatches, 388 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 16226 ImplicationChecksByTransitivity, 24.9s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1968occurred in iteration=8, InterpolantAutomatonStates: 274, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 9 MinimizatonAttempts, 906 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 4540 PreInvPairs, 5502 NumberOfFragments, 3722 HoareAnnotationTreeSize, 4540 FomulaSimplifications, 51707 FormulaSimplificationTreeSizeReduction, 3.2s HoareSimplificationTime, 38 FomulaSimplificationsInter, 123845 FormulaSimplificationTreeSizeReductionInter, 22.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 3.5s InterpolantComputationTime, 702 NumberOfCodeBlocks, 702 NumberOfCodeBlocksAsserted, 12 NumberOfCheckSat, 923 ConstructedInterpolants, 0 QuantifiedInterpolants, 2386 SizeOfPredicates, 26 NumberOfNonLiveVariables, 1515 ConjunctsInSsa, 65 ConjunctsInUnsatCore, 15 InterpolantComputations, 6 PerfectInterpolantSequences, 417/467 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 820]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((\old(pumpRunning) == 0 || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || (aux-isMethaneAlarm()-aux == methaneLevelCritical && 2 <= waterLevel)) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) - InvariantResult [Line: 710]: Loop Invariant Derived loop invariant: ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive)) && (!(\old(waterLevel) == 2) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 933]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && tmp == 1) && waterLevel == 1 - InvariantResult [Line: 114]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1) - InvariantResult [Line: 193]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && tmp == 1) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive) - InvariantResult [Line: 72]: Loop Invariant Derived loop invariant: ((((((((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && !(\old(waterLevel) == 1)) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && (\old(waterLevel) == waterLevel || waterLevel == 1)) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && (((((((((!(pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || (((((pumpRunning == 0 && 2 == waterLevel) && !(\old(waterLevel) == 1)) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && pumpRunning == switchedOnBeforeTS) && tmp == 2)) || ((\old(waterLevel) == waterLevel && pumpRunning == 1) && tmp == 2))) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || (methaneLevelCritical == 0 && !(\old(pumpRunning) == 1))) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((!(pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || methaneLevelCritical == 0) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(pumpRunning) == 0) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 2)) || 0 == systemActive) || tmp == 2)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || (methaneLevelCritical == 0 && !(\old(pumpRunning) == 1))) || !(methaneLevelCritical == 0)) || 0 == systemActive) || pumpRunning == 1) - InvariantResult [Line: 790]: Loop Invariant Derived loop invariant: (((((((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1) && (((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || ((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) - InvariantResult [Line: 840]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 67]: Loop Invariant Derived loop invariant: ((((((((((((\old(waterLevel) == waterLevel && aux-isPumpRunning()-aux == pumpRunning) || !(\old(waterLevel) == 2)) || 0 == systemActive) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(aux-isPumpRunning()-aux == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && pumpRunning == switchedOnBeforeTS) && aux-isPumpRunning()-aux == pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && (((((!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || pumpRunning == 0) || ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && !(\old(waterLevel) <= 0))) || waterLevel <= 0) || 0 == systemActive)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && !(\old(waterLevel) <= 0))) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((\old(waterLevel) == waterLevel || waterLevel == 1) && aux-isPumpRunning()-aux == pumpRunning) && pumpRunning == 1)) || 0 == systemActive)) && (((((!(pumpRunning == 0) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((\old(waterLevel) == waterLevel || waterLevel == 1) && aux-isPumpRunning()-aux == pumpRunning) && pumpRunning == 1)) || 0 == systemActive) - InvariantResult [Line: 104]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 954]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && waterLevel <= 2) && tmp == 1) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive)) || ((((pumpRunning == 0 && waterLevel <= 1) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || (((2 == waterLevel && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive)) - InvariantResult [Line: 735]: Loop Invariant Derived loop invariant: (((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && ((((((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (((!(pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 924]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 934]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0 && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive)) || (((((methaneLevelCritical == 0 && splverifierCounter == 0) && waterLevel <= 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || ((((2 == waterLevel && (!(methaneLevelCritical == 0) || pumpRunning == 1)) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || ((((pumpRunning == 0 && 2 == waterLevel) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || (((((pumpRunning == 0 && waterLevel <= 1) && !(methaneLevelCritical == 0)) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || (((((methaneLevelCritical == 0 && splverifierCounter == 0) && tmp == 1) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive)) - InvariantResult [Line: 193]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 782]: Loop Invariant Derived loop invariant: (((((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || pumpRunning == 1)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || methaneLevelCritical == 0) || \old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1))) && ((((((((!(pumpRunning == 0) && tmp == methaneLevelCritical) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive)) && ((((((waterLevel == 1 && pumpRunning == 1) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (((!(pumpRunning == 0) && tmp == methaneLevelCritical) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((2 == waterLevel && methaneLevelCritical == 0) && \old(waterLevel) == waterLevel) && !(0 == systemActive)) && pumpRunning == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 760]: Loop Invariant Derived loop invariant: ((((!(methaneLevelCritical == 0) || !(waterLevel <= 2)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) RESULT: Ultimate proved your program to be correct! [2022-11-03 03:46:46,894 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1838d7a3-edf8-4e5f-bee2-e66245ad14a2/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE