./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 1ef39c14b0f41147d1df64069011556a64ce74ff520b071f62407c2225292c50 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 03:36:17,526 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 03:36:17,528 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 03:36:17,580 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 03:36:17,580 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 03:36:17,584 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 03:36:17,587 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 03:36:17,590 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 03:36:17,592 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 03:36:17,600 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 03:36:17,601 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 03:36:17,604 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 03:36:17,604 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 03:36:17,607 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 03:36:17,609 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 03:36:17,611 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 03:36:17,613 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 03:36:17,614 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 03:36:17,615 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 03:36:17,623 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 03:36:17,624 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 03:36:17,625 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 03:36:17,629 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 03:36:17,630 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 03:36:17,638 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 03:36:17,638 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 03:36:17,639 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 03:36:17,641 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 03:36:17,642 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 03:36:17,643 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 03:36:17,643 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 03:36:17,644 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 03:36:17,646 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 03:36:17,649 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 03:36:17,650 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 03:36:17,650 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 03:36:17,651 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 03:36:17,651 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 03:36:17,652 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 03:36:17,652 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 03:36:17,653 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 03:36:17,654 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 03:36:17,692 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 03:36:17,693 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 03:36:17,693 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 03:36:17,694 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 03:36:17,695 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 03:36:17,695 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 03:36:17,695 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 03:36:17,695 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 03:36:17,696 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 03:36:17,696 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 03:36:17,697 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 03:36:17,697 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 03:36:17,697 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 03:36:17,697 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 03:36:17,697 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 03:36:17,698 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 03:36:17,698 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 03:36:17,698 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 03:36:17,699 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 03:36:17,699 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 03:36:17,699 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 03:36:17,699 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 03:36:17,700 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 03:36:17,701 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 03:36:17,701 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 03:36:17,701 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 03:36:17,701 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 03:36:17,702 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:36:17,702 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 03:36:17,702 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 03:36:17,702 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 03:36:17,702 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 03:36:17,703 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 03:36:17,703 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 03:36:17,703 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 03:36:17,703 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 03:36:17,703 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 1ef39c14b0f41147d1df64069011556a64ce74ff520b071f62407c2225292c50 [2022-11-03 03:36:18,018 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 03:36:18,040 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 03:36:18,043 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 03:36:18,044 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 03:36:18,045 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 03:36:18,046 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c [2022-11-03 03:36:18,126 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/data/231fe7850/2f2876f0e2a04b8f98e36fdb9e5ac1ae/FLAG3b9082ea2 [2022-11-03 03:36:18,745 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 03:36:18,748 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c [2022-11-03 03:36:18,766 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/data/231fe7850/2f2876f0e2a04b8f98e36fdb9e5ac1ae/FLAG3b9082ea2 [2022-11-03 03:36:19,015 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/data/231fe7850/2f2876f0e2a04b8f98e36fdb9e5ac1ae [2022-11-03 03:36:19,021 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 03:36:19,023 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 03:36:19,026 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 03:36:19,027 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 03:36:19,030 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 03:36:19,031 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,034 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7950ac4d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19, skipping insertion in model container [2022-11-03 03:36:19,035 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,043 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 03:36:19,105 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 03:36:19,426 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c[18485,18498] [2022-11-03 03:36:19,431 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:36:19,441 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 03:36:19,545 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c[18485,18498] [2022-11-03 03:36:19,547 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 03:36:19,564 INFO L208 MainTranslator]: Completed translation [2022-11-03 03:36:19,565 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19 WrapperNode [2022-11-03 03:36:19,565 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 03:36:19,566 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 03:36:19,566 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 03:36:19,566 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 03:36:19,574 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,588 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,614 INFO L138 Inliner]: procedures = 58, calls = 159, calls flagged for inlining = 25, calls inlined = 21, statements flattened = 265 [2022-11-03 03:36:19,615 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 03:36:19,615 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 03:36:19,615 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 03:36:19,616 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 03:36:19,625 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,626 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,629 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,629 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,634 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,639 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,641 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,642 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,645 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 03:36:19,646 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 03:36:19,646 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 03:36:19,646 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 03:36:19,647 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (1/1) ... [2022-11-03 03:36:19,654 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 03:36:19,666 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:36:19,694 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 03:36:19,712 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 03:36:19,759 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 03:36:19,759 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 03:36:19,759 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 03:36:19,759 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 03:36:19,759 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 03:36:19,760 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 03:36:19,760 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 03:36:19,760 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:36:19,760 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:36:19,760 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 03:36:19,761 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 03:36:19,761 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-03 03:36:19,761 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-03 03:36:19,761 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-03 03:36:19,761 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-03 03:36:19,761 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 03:36:19,762 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 03:36:19,763 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 03:36:19,763 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 03:36:19,763 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 03:36:19,889 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 03:36:19,891 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 03:36:20,344 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 03:36:20,465 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 03:36:20,465 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 03:36:20,468 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:36:20 BoogieIcfgContainer [2022-11-03 03:36:20,468 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 03:36:20,471 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 03:36:20,471 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 03:36:20,475 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 03:36:20,475 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 03:36:19" (1/3) ... [2022-11-03 03:36:20,476 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@30feda08 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:36:20, skipping insertion in model container [2022-11-03 03:36:20,476 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 03:36:19" (2/3) ... [2022-11-03 03:36:20,476 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@30feda08 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 03:36:20, skipping insertion in model container [2022-11-03 03:36:20,476 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:36:20" (3/3) ... [2022-11-03 03:36:20,478 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product51.cil.c [2022-11-03 03:36:20,497 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 03:36:20,497 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 03:36:20,551 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 03:36:20,559 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@79b852d6, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 03:36:20,559 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 03:36:20,564 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-03 03:36:20,574 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 03:36:20,575 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:20,575 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:20,576 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:20,582 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:20,582 INFO L85 PathProgramCache]: Analyzing trace with hash -51587778, now seen corresponding path program 1 times [2022-11-03 03:36:20,593 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:20,593 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1169122661] [2022-11-03 03:36:20,594 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:20,594 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:20,721 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:20,804 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:36:20,805 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:20,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1169122661] [2022-11-03 03:36:20,806 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1169122661] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:20,806 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:20,806 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 03:36:20,808 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1796325182] [2022-11-03 03:36:20,809 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:20,813 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 03:36:20,813 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:20,841 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 03:36:20,842 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:36:20,844 INFO L87 Difference]: Start difference. First operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:20,946 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:20,946 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2022-11-03 03:36:20,950 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 03:36:20,952 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-03 03:36:20,952 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:20,968 INFO L225 Difference]: With dead ends: 130 [2022-11-03 03:36:20,969 INFO L226 Difference]: Without dead ends: 61 [2022-11-03 03:36:20,974 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 03:36:20,979 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 69 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:20,981 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 69 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:36:21,003 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-03 03:36:21,027 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-03 03:36:21,028 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 39 states have (on average 1.358974358974359) internal successors, (53), 47 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-03 03:36:21,030 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 80 transitions. [2022-11-03 03:36:21,032 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 80 transitions. Word has length 21 [2022-11-03 03:36:21,032 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:21,032 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 80 transitions. [2022-11-03 03:36:21,033 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:21,033 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 80 transitions. [2022-11-03 03:36:21,035 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-03 03:36:21,035 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:21,035 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:21,035 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 03:36:21,036 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:21,036 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:21,037 INFO L85 PathProgramCache]: Analyzing trace with hash -421310611, now seen corresponding path program 1 times [2022-11-03 03:36:21,037 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:21,037 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1558971840] [2022-11-03 03:36:21,037 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:21,038 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:21,064 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:21,161 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:36:21,162 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:21,162 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1558971840] [2022-11-03 03:36:21,162 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1558971840] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:21,162 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:21,162 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 03:36:21,163 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [207130520] [2022-11-03 03:36:21,163 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:21,164 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:36:21,164 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:21,165 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:36:21,165 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:36:21,166 INFO L87 Difference]: Start difference. First operand 61 states and 80 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:21,215 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:21,216 INFO L93 Difference]: Finished difference Result 94 states and 122 transitions. [2022-11-03 03:36:21,216 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:36:21,217 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-03 03:36:21,217 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:21,218 INFO L225 Difference]: With dead ends: 94 [2022-11-03 03:36:21,218 INFO L226 Difference]: Without dead ends: 53 [2022-11-03 03:36:21,219 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 03:36:21,221 INFO L413 NwaCegarLoop]: 55 mSDtfsCounter, 14 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 93 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:21,221 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 93 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 03:36:21,222 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-03 03:36:21,228 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-03 03:36:21,229 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3823529411764706) internal successors, (47), 42 states have internal predecessors, (47), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-03 03:36:21,230 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 69 transitions. [2022-11-03 03:36:21,231 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 69 transitions. Word has length 22 [2022-11-03 03:36:21,231 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:21,231 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 69 transitions. [2022-11-03 03:36:21,231 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:21,232 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 69 transitions. [2022-11-03 03:36:21,233 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-03 03:36:21,233 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:21,233 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:21,234 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 03:36:21,234 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:21,235 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:21,235 INFO L85 PathProgramCache]: Analyzing trace with hash -354328816, now seen corresponding path program 1 times [2022-11-03 03:36:21,235 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:21,235 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1823072834] [2022-11-03 03:36:21,236 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:21,236 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:21,282 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:21,504 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:36:21,504 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:21,504 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1823072834] [2022-11-03 03:36:21,505 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1823072834] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:21,505 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:21,505 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:36:21,505 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [558542000] [2022-11-03 03:36:21,506 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:21,506 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:36:21,506 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:21,507 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:36:21,507 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:36:21,508 INFO L87 Difference]: Start difference. First operand 53 states and 69 transitions. Second operand has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 03:36:21,667 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:21,667 INFO L93 Difference]: Finished difference Result 154 states and 207 transitions. [2022-11-03 03:36:21,668 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:36:21,668 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2022-11-03 03:36:21,668 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:21,670 INFO L225 Difference]: With dead ends: 154 [2022-11-03 03:36:21,670 INFO L226 Difference]: Without dead ends: 103 [2022-11-03 03:36:21,671 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 03:36:21,672 INFO L413 NwaCegarLoop]: 70 mSDtfsCounter, 81 mSDsluCounter, 115 mSDsCounter, 0 mSdLazyCounter, 71 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 81 SdHoareTripleChecker+Valid, 163 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 71 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:21,673 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [81 Valid, 163 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 71 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:36:21,674 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 103 states. [2022-11-03 03:36:21,689 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 103 to 86. [2022-11-03 03:36:21,690 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 56 states have (on average 1.375) internal successors, (77), 67 states have internal predecessors, (77), 17 states have call successors, (17), 12 states have call predecessors, (17), 12 states have return successors, (18), 13 states have call predecessors, (18), 17 states have call successors, (18) [2022-11-03 03:36:21,691 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 112 transitions. [2022-11-03 03:36:21,692 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 112 transitions. Word has length 25 [2022-11-03 03:36:21,692 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:21,692 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 112 transitions. [2022-11-03 03:36:21,693 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-03 03:36:21,693 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 112 transitions. [2022-11-03 03:36:21,694 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-03 03:36:21,695 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:21,695 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:21,695 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 03:36:21,695 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:21,696 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:21,696 INFO L85 PathProgramCache]: Analyzing trace with hash 1724918103, now seen corresponding path program 1 times [2022-11-03 03:36:21,697 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:21,697 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2133046541] [2022-11-03 03:36:21,697 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:21,697 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:21,720 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:21,943 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 03:36:21,943 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:21,944 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2133046541] [2022-11-03 03:36:21,944 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2133046541] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:21,944 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:21,944 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 03:36:21,945 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1979496049] [2022-11-03 03:36:21,946 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:21,948 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 03:36:21,948 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:21,949 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 03:36:21,949 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:36:21,950 INFO L87 Difference]: Start difference. First operand 86 states and 112 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:22,149 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:22,149 INFO L93 Difference]: Finished difference Result 209 states and 282 transitions. [2022-11-03 03:36:22,150 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 03:36:22,150 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2022-11-03 03:36:22,151 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:22,157 INFO L225 Difference]: With dead ends: 209 [2022-11-03 03:36:22,157 INFO L226 Difference]: Without dead ends: 125 [2022-11-03 03:36:22,173 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 03:36:22,180 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 34 mSDsluCounter, 253 mSDsCounter, 0 mSdLazyCounter, 117 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 283 SdHoareTripleChecker+Invalid, 126 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 117 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:22,184 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [35 Valid, 283 Invalid, 126 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 117 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:36:22,186 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 125 states. [2022-11-03 03:36:22,211 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 125 to 118. [2022-11-03 03:36:22,214 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 118 states, 79 states have (on average 1.2911392405063291) internal successors, (102), 89 states have internal predecessors, (102), 21 states have call successors, (21), 17 states have call predecessors, (21), 17 states have return successors, (27), 20 states have call predecessors, (27), 21 states have call successors, (27) [2022-11-03 03:36:22,219 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 118 states to 118 states and 150 transitions. [2022-11-03 03:36:22,219 INFO L78 Accepts]: Start accepts. Automaton has 118 states and 150 transitions. Word has length 28 [2022-11-03 03:36:22,220 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:22,220 INFO L495 AbstractCegarLoop]: Abstraction has 118 states and 150 transitions. [2022-11-03 03:36:22,220 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 03:36:22,220 INFO L276 IsEmpty]: Start isEmpty. Operand 118 states and 150 transitions. [2022-11-03 03:36:22,224 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-03 03:36:22,226 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:22,227 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:22,227 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 03:36:22,227 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:22,228 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:22,229 INFO L85 PathProgramCache]: Analyzing trace with hash -1342169840, now seen corresponding path program 1 times [2022-11-03 03:36:22,230 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:22,230 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1531071286] [2022-11-03 03:36:22,230 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:22,231 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:22,257 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:22,742 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:36:22,742 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:22,742 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1531071286] [2022-11-03 03:36:22,743 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1531071286] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:22,743 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:22,744 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-03 03:36:22,746 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [502862781] [2022-11-03 03:36:22,748 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:22,749 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-03 03:36:22,749 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:22,750 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-03 03:36:22,750 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-03 03:36:22,751 INFO L87 Difference]: Start difference. First operand 118 states and 150 transitions. Second operand has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 03:36:22,978 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:22,979 INFO L93 Difference]: Finished difference Result 370 states and 474 transitions. [2022-11-03 03:36:22,979 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-03 03:36:22,979 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 33 [2022-11-03 03:36:22,980 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:22,982 INFO L225 Difference]: With dead ends: 370 [2022-11-03 03:36:22,982 INFO L226 Difference]: Without dead ends: 254 [2022-11-03 03:36:22,983 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=20, Invalid=36, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:36:22,984 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 99 mSDsluCounter, 234 mSDsCounter, 0 mSdLazyCounter, 183 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 101 SdHoareTripleChecker+Valid, 300 SdHoareTripleChecker+Invalid, 196 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 183 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:22,984 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [101 Valid, 300 Invalid, 196 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 183 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 03:36:22,985 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 254 states. [2022-11-03 03:36:23,020 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 254 to 249. [2022-11-03 03:36:23,021 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 249 states, 166 states have (on average 1.2891566265060241) internal successors, (214), 185 states have internal predecessors, (214), 45 states have call successors, (45), 38 states have call predecessors, (45), 37 states have return successors, (59), 40 states have call predecessors, (59), 45 states have call successors, (59) [2022-11-03 03:36:23,023 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 249 states to 249 states and 318 transitions. [2022-11-03 03:36:23,023 INFO L78 Accepts]: Start accepts. Automaton has 249 states and 318 transitions. Word has length 33 [2022-11-03 03:36:23,024 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:23,024 INFO L495 AbstractCegarLoop]: Abstraction has 249 states and 318 transitions. [2022-11-03 03:36:23,024 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 03:36:23,024 INFO L276 IsEmpty]: Start isEmpty. Operand 249 states and 318 transitions. [2022-11-03 03:36:23,026 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-03 03:36:23,026 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:23,027 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:23,027 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 03:36:23,027 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:23,027 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:23,028 INFO L85 PathProgramCache]: Analyzing trace with hash -902427270, now seen corresponding path program 1 times [2022-11-03 03:36:23,028 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:23,028 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1144778297] [2022-11-03 03:36:23,028 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:23,029 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:23,049 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:23,415 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 03:36:23,416 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:23,416 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1144778297] [2022-11-03 03:36:23,416 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1144778297] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:23,417 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:23,417 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 03:36:23,417 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1569378264] [2022-11-03 03:36:23,417 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:23,418 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 03:36:23,418 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:23,419 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 03:36:23,419 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-03 03:36:23,420 INFO L87 Difference]: Start difference. First operand 249 states and 318 transitions. Second operand has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:36:23,944 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:23,944 INFO L93 Difference]: Finished difference Result 557 states and 734 transitions. [2022-11-03 03:36:23,945 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 03:36:23,945 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 36 [2022-11-03 03:36:23,946 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:23,953 INFO L225 Difference]: With dead ends: 557 [2022-11-03 03:36:23,954 INFO L226 Difference]: Without dead ends: 401 [2022-11-03 03:36:23,955 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 4 SyntacticMatches, 1 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 31 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-03 03:36:23,956 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 233 mSDsluCounter, 215 mSDsCounter, 0 mSdLazyCounter, 298 mSolverCounterSat, 97 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 239 SdHoareTripleChecker+Valid, 277 SdHoareTripleChecker+Invalid, 395 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 97 IncrementalHoareTripleChecker+Valid, 298 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:23,959 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [239 Valid, 277 Invalid, 395 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [97 Valid, 298 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 03:36:23,961 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 401 states. [2022-11-03 03:36:24,018 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 401 to 347. [2022-11-03 03:36:24,019 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 347 states, 235 states have (on average 1.2808510638297872) internal successors, (301), 261 states have internal predecessors, (301), 60 states have call successors, (60), 47 states have call predecessors, (60), 51 states have return successors, (82), 58 states have call predecessors, (82), 60 states have call successors, (82) [2022-11-03 03:36:24,021 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 347 states to 347 states and 443 transitions. [2022-11-03 03:36:24,021 INFO L78 Accepts]: Start accepts. Automaton has 347 states and 443 transitions. Word has length 36 [2022-11-03 03:36:24,022 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:24,022 INFO L495 AbstractCegarLoop]: Abstraction has 347 states and 443 transitions. [2022-11-03 03:36:24,022 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 03:36:24,022 INFO L276 IsEmpty]: Start isEmpty. Operand 347 states and 443 transitions. [2022-11-03 03:36:24,024 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-03 03:36:24,024 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:24,024 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:24,025 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 03:36:24,025 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:24,025 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:24,025 INFO L85 PathProgramCache]: Analyzing trace with hash -1121294904, now seen corresponding path program 1 times [2022-11-03 03:36:24,026 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:24,026 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1005685570] [2022-11-03 03:36:24,026 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:24,026 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:24,043 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:24,080 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 17 proven. 0 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-03 03:36:24,080 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:24,081 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1005685570] [2022-11-03 03:36:24,081 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1005685570] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:24,081 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 03:36:24,081 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 03:36:24,081 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1752747802] [2022-11-03 03:36:24,082 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:24,082 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 03:36:24,082 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:24,083 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 03:36:24,083 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:36:24,083 INFO L87 Difference]: Start difference. First operand 347 states and 443 transitions. Second operand has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-03 03:36:24,213 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:24,214 INFO L93 Difference]: Finished difference Result 698 states and 890 transitions. [2022-11-03 03:36:24,215 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 03:36:24,215 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) Word has length 65 [2022-11-03 03:36:24,215 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:24,219 INFO L225 Difference]: With dead ends: 698 [2022-11-03 03:36:24,219 INFO L226 Difference]: Without dead ends: 247 [2022-11-03 03:36:24,220 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 03:36:24,225 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 94 mSDsluCounter, 67 mSDsCounter, 0 mSdLazyCounter, 80 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 94 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 82 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 80 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:24,225 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [94 Valid, 128 Invalid, 82 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 80 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:36:24,227 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 247 states. [2022-11-03 03:36:24,272 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 247 to 247. [2022-11-03 03:36:24,273 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 247 states, 167 states have (on average 1.2395209580838322) internal successors, (207), 184 states have internal predecessors, (207), 42 states have call successors, (42), 32 states have call predecessors, (42), 37 states have return successors, (57), 42 states have call predecessors, (57), 42 states have call successors, (57) [2022-11-03 03:36:24,276 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 247 states to 247 states and 306 transitions. [2022-11-03 03:36:24,277 INFO L78 Accepts]: Start accepts. Automaton has 247 states and 306 transitions. Word has length 65 [2022-11-03 03:36:24,277 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:24,277 INFO L495 AbstractCegarLoop]: Abstraction has 247 states and 306 transitions. [2022-11-03 03:36:24,277 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-03 03:36:24,278 INFO L276 IsEmpty]: Start isEmpty. Operand 247 states and 306 transitions. [2022-11-03 03:36:24,279 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2022-11-03 03:36:24,280 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:24,280 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:24,280 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-03 03:36:24,281 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:24,281 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:24,281 INFO L85 PathProgramCache]: Analyzing trace with hash 641510741, now seen corresponding path program 1 times [2022-11-03 03:36:24,282 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:24,282 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [872231203] [2022-11-03 03:36:24,282 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:24,282 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:24,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:24,452 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 17 proven. 2 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-03 03:36:24,454 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:24,459 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [872231203] [2022-11-03 03:36:24,459 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [872231203] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:36:24,460 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [199059071] [2022-11-03 03:36:24,460 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:24,460 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:36:24,460 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:36:24,466 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:36:24,482 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 03:36:24,607 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:24,624 INFO L263 TraceCheckSpWp]: Trace formula consists of 440 conjuncts, 4 conjunts are in the unsatisfiable core [2022-11-03 03:36:24,629 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:36:24,765 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:36:24,765 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-03 03:36:24,765 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [199059071] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 03:36:24,765 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-03 03:36:24,766 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [5] total 6 [2022-11-03 03:36:24,766 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1360173148] [2022-11-03 03:36:24,766 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 03:36:24,766 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 03:36:24,767 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:24,767 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 03:36:24,767 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:36:24,767 INFO L87 Difference]: Start difference. First operand 247 states and 306 transitions. Second operand has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:36:24,860 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:24,860 INFO L93 Difference]: Finished difference Result 369 states and 461 transitions. [2022-11-03 03:36:24,878 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 03:36:24,879 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 62 [2022-11-03 03:36:24,879 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:24,880 INFO L225 Difference]: With dead ends: 369 [2022-11-03 03:36:24,880 INFO L226 Difference]: Without dead ends: 237 [2022-11-03 03:36:24,881 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 68 GetRequests, 64 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2022-11-03 03:36:24,882 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 30 mSDsluCounter, 43 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 30 SdHoareTripleChecker+Valid, 113 SdHoareTripleChecker+Invalid, 32 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:24,882 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [30 Valid, 113 Invalid, 32 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 03:36:24,883 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2022-11-03 03:36:24,913 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 237. [2022-11-03 03:36:24,914 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 237 states, 160 states have (on average 1.2125) internal successors, (194), 176 states have internal predecessors, (194), 40 states have call successors, (40), 32 states have call predecessors, (40), 36 states have return successors, (47), 40 states have call predecessors, (47), 40 states have call successors, (47) [2022-11-03 03:36:24,915 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 237 states to 237 states and 281 transitions. [2022-11-03 03:36:24,917 INFO L78 Accepts]: Start accepts. Automaton has 237 states and 281 transitions. Word has length 62 [2022-11-03 03:36:24,917 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:24,918 INFO L495 AbstractCegarLoop]: Abstraction has 237 states and 281 transitions. [2022-11-03 03:36:24,918 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-03 03:36:24,918 INFO L276 IsEmpty]: Start isEmpty. Operand 237 states and 281 transitions. [2022-11-03 03:36:24,919 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-03 03:36:24,919 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:24,919 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:24,959 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-03 03:36:25,134 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable7 [2022-11-03 03:36:25,134 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:25,134 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:25,135 INFO L85 PathProgramCache]: Analyzing trace with hash -1725898309, now seen corresponding path program 1 times [2022-11-03 03:36:25,135 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:25,135 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [33407694] [2022-11-03 03:36:25,135 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:25,135 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:25,154 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:25,302 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 03:36:25,302 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:25,302 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [33407694] [2022-11-03 03:36:25,302 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [33407694] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:36:25,302 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1642884019] [2022-11-03 03:36:25,303 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:25,303 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:36:25,303 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:36:25,304 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:36:25,334 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 03:36:25,424 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:25,426 INFO L263 TraceCheckSpWp]: Trace formula consists of 445 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-03 03:36:25,433 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:36:25,601 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 19 proven. 7 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 03:36:25,601 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:36:25,805 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 03:36:25,806 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1642884019] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:36:25,806 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [2015600150] [2022-11-03 03:36:25,827 INFO L159 IcfgInterpreter]: Started Sifa with 42 locations of interest [2022-11-03 03:36:25,827 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:36:25,831 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:36:25,837 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:36:25,838 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:36:35,020 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 32 for LOIs [2022-11-03 03:36:35,025 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 29 for LOIs [2022-11-03 03:36:35,403 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2022-11-03 03:36:35,416 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 72 for LOIs [2022-11-03 03:36:35,705 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 48 for LOIs [2022-11-03 03:36:35,710 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:36:41,557 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '6741#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483647) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483648)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= 0 ~methaneLevelCritical~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:36:41,558 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:36:41,558 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:36:41,558 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 13 [2022-11-03 03:36:41,558 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1976264738] [2022-11-03 03:36:41,558 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:36:41,559 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-03 03:36:41,559 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:41,560 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-03 03:36:41,560 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=203, Invalid=1689, Unknown=0, NotChecked=0, Total=1892 [2022-11-03 03:36:41,561 INFO L87 Difference]: Start difference. First operand 237 states and 281 transitions. Second operand has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-03 03:36:42,219 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:36:42,219 INFO L93 Difference]: Finished difference Result 308 states and 374 transitions. [2022-11-03 03:36:42,219 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-11-03 03:36:42,219 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) Word has length 65 [2022-11-03 03:36:42,220 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:36:42,221 INFO L225 Difference]: With dead ends: 308 [2022-11-03 03:36:42,222 INFO L226 Difference]: Without dead ends: 306 [2022-11-03 03:36:42,223 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 225 GetRequests, 164 SyntacticMatches, 4 SemanticMatches, 57 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1133 ImplicationChecksByTransitivity, 6.2s TimeCoverageRelationStatistics Valid=332, Invalid=3090, Unknown=0, NotChecked=0, Total=3422 [2022-11-03 03:36:42,224 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 167 mSDsluCounter, 794 mSDsCounter, 0 mSdLazyCounter, 417 mSolverCounterSat, 91 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 174 SdHoareTripleChecker+Valid, 780 SdHoareTripleChecker+Invalid, 508 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 91 IncrementalHoareTripleChecker+Valid, 417 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-03 03:36:42,224 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [174 Valid, 780 Invalid, 508 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [91 Valid, 417 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-03 03:36:42,225 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2022-11-03 03:36:42,254 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 285. [2022-11-03 03:36:42,255 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 191 states have (on average 1.2041884816753927) internal successors, (230), 212 states have internal predecessors, (230), 49 states have call successors, (49), 40 states have call predecessors, (49), 44 states have return successors, (60), 48 states have call predecessors, (60), 49 states have call successors, (60) [2022-11-03 03:36:42,257 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 339 transitions. [2022-11-03 03:36:42,258 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 339 transitions. Word has length 65 [2022-11-03 03:36:42,258 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:36:42,258 INFO L495 AbstractCegarLoop]: Abstraction has 285 states and 339 transitions. [2022-11-03 03:36:42,258 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-03 03:36:42,259 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 339 transitions. [2022-11-03 03:36:42,261 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 87 [2022-11-03 03:36:42,261 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:36:42,261 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:36:42,304 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-03 03:36:42,474 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:36:42,474 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:36:42,475 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:36:42,475 INFO L85 PathProgramCache]: Analyzing trace with hash -932444730, now seen corresponding path program 1 times [2022-11-03 03:36:42,475 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:36:42,475 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2020427440] [2022-11-03 03:36:42,475 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:42,475 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:36:42,500 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:42,737 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 35 proven. 3 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-11-03 03:36:42,737 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:36:42,737 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2020427440] [2022-11-03 03:36:42,738 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2020427440] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:36:42,738 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2005733494] [2022-11-03 03:36:42,738 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:36:42,738 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:36:42,738 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:36:42,739 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:36:42,764 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 03:36:42,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:36:42,863 INFO L263 TraceCheckSpWp]: Trace formula consists of 528 conjuncts, 18 conjunts are in the unsatisfiable core [2022-11-03 03:36:42,866 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:36:43,078 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 61 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-03 03:36:43,078 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:36:43,424 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 48 proven. 3 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-03 03:36:43,424 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2005733494] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:36:43,425 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1266764833] [2022-11-03 03:36:43,433 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-03 03:36:43,434 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:36:43,435 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:36:43,435 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:36:43,435 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:36:51,682 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 309 for LOIs [2022-11-03 03:36:51,741 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-03 03:36:52,035 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 40 for LOIs [2022-11-03 03:36:52,040 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-03 03:36:52,055 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 34 for LOIs [2022-11-03 03:36:52,058 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:36:58,393 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '8232#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:36:58,393 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:36:58,393 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:36:58,394 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 9] total 20 [2022-11-03 03:36:58,394 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2135270431] [2022-11-03 03:36:58,394 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:36:58,395 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-03 03:36:58,395 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:36:58,395 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-03 03:36:58,396 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=283, Invalid=2369, Unknown=0, NotChecked=0, Total=2652 [2022-11-03 03:36:58,397 INFO L87 Difference]: Start difference. First operand 285 states and 339 transitions. Second operand has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-03 03:37:00,208 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:37:00,208 INFO L93 Difference]: Finished difference Result 848 states and 1107 transitions. [2022-11-03 03:37:00,208 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-03 03:37:00,209 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) Word has length 86 [2022-11-03 03:37:00,210 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:37:00,219 INFO L225 Difference]: With dead ends: 848 [2022-11-03 03:37:00,219 INFO L226 Difference]: Without dead ends: 557 [2022-11-03 03:37:00,225 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 311 GetRequests, 234 SyntacticMatches, 0 SemanticMatches, 77 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2065 ImplicationChecksByTransitivity, 7.3s TimeCoverageRelationStatistics Valid=655, Invalid=5507, Unknown=0, NotChecked=0, Total=6162 [2022-11-03 03:37:00,226 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 612 mSDsluCounter, 616 mSDsCounter, 0 mSdLazyCounter, 1042 mSolverCounterSat, 427 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 615 SdHoareTripleChecker+Valid, 629 SdHoareTripleChecker+Invalid, 1469 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 427 IncrementalHoareTripleChecker+Valid, 1042 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2022-11-03 03:37:00,226 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [615 Valid, 629 Invalid, 1469 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [427 Valid, 1042 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2022-11-03 03:37:00,227 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 557 states. [2022-11-03 03:37:00,268 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 557 to 346. [2022-11-03 03:37:00,269 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 346 states, 233 states have (on average 1.167381974248927) internal successors, (272), 255 states have internal predecessors, (272), 56 states have call successors, (56), 50 states have call predecessors, (56), 56 states have return successors, (71), 57 states have call predecessors, (71), 56 states have call successors, (71) [2022-11-03 03:37:00,270 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 346 states to 346 states and 399 transitions. [2022-11-03 03:37:00,271 INFO L78 Accepts]: Start accepts. Automaton has 346 states and 399 transitions. Word has length 86 [2022-11-03 03:37:00,271 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:37:00,271 INFO L495 AbstractCegarLoop]: Abstraction has 346 states and 399 transitions. [2022-11-03 03:37:00,272 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-03 03:37:00,272 INFO L276 IsEmpty]: Start isEmpty. Operand 346 states and 399 transitions. [2022-11-03 03:37:00,273 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2022-11-03 03:37:00,273 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 03:37:00,274 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:37:00,298 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 03:37:00,478 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-03 03:37:00,479 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 03:37:00,479 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 03:37:00,479 INFO L85 PathProgramCache]: Analyzing trace with hash -57351158, now seen corresponding path program 1 times [2022-11-03 03:37:00,479 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 03:37:00,479 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1272323010] [2022-11-03 03:37:00,479 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:37:00,480 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 03:37:00,499 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:37:01,635 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 26 proven. 31 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 03:37:01,635 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 03:37:01,635 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1272323010] [2022-11-03 03:37:01,635 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1272323010] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 03:37:01,635 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1567593483] [2022-11-03 03:37:01,635 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 03:37:01,636 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 03:37:01,636 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 03:37:01,637 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 03:37:01,662 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-03 03:37:01,767 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 03:37:01,770 INFO L263 TraceCheckSpWp]: Trace formula consists of 542 conjuncts, 30 conjunts are in the unsatisfiable core [2022-11-03 03:37:01,773 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 03:37:02,180 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 57 proven. 16 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 03:37:02,180 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 03:37:02,724 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 52 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 03:37:02,724 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1567593483] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 03:37:02,724 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [41286890] [2022-11-03 03:37:02,729 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-03 03:37:02,730 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 03:37:02,731 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 03:37:02,731 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 03:37:02,731 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 03:37:07,653 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 55 for LOIs [2022-11-03 03:37:07,660 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-03 03:37:07,974 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 40 for LOIs [2022-11-03 03:37:07,979 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-03 03:37:07,995 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 34 for LOIs [2022-11-03 03:37:08,001 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 03:37:14,336 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '10696#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-03 03:37:14,336 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 03:37:14,336 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 03:37:14,336 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [19, 11, 11] total 33 [2022-11-03 03:37:14,337 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1634555830] [2022-11-03 03:37:14,337 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 03:37:14,338 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 33 states [2022-11-03 03:37:14,338 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 03:37:14,338 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 33 interpolants. [2022-11-03 03:37:14,339 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=400, Invalid=3632, Unknown=0, NotChecked=0, Total=4032 [2022-11-03 03:37:14,339 INFO L87 Difference]: Start difference. First operand 346 states and 399 transitions. Second operand has 33 states, 33 states have (on average 4.454545454545454) internal successors, (147), 33 states have internal predecessors, (147), 17 states have call successors, (29), 8 states have call predecessors, (29), 12 states have return successors, (28), 18 states have call predecessors, (28), 16 states have call successors, (28) [2022-11-03 03:37:17,613 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 03:37:17,613 INFO L93 Difference]: Finished difference Result 857 states and 1019 transitions. [2022-11-03 03:37:17,613 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 46 states. [2022-11-03 03:37:17,614 INFO L78 Accepts]: Start accepts. Automaton has has 33 states, 33 states have (on average 4.454545454545454) internal successors, (147), 33 states have internal predecessors, (147), 17 states have call successors, (29), 8 states have call predecessors, (29), 12 states have return successors, (28), 18 states have call predecessors, (28), 16 states have call successors, (28) Word has length 91 [2022-11-03 03:37:17,614 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 03:37:17,614 INFO L225 Difference]: With dead ends: 857 [2022-11-03 03:37:17,615 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 03:37:17,619 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 362 GetRequests, 253 SyntacticMatches, 4 SemanticMatches, 105 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3954 ImplicationChecksByTransitivity, 8.4s TimeCoverageRelationStatistics Valid=1294, Invalid=10048, Unknown=0, NotChecked=0, Total=11342 [2022-11-03 03:37:17,620 INFO L413 NwaCegarLoop]: 144 mSDtfsCounter, 1660 mSDsluCounter, 1201 mSDsCounter, 0 mSdLazyCounter, 1973 mSolverCounterSat, 1178 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1661 SdHoareTripleChecker+Valid, 1212 SdHoareTripleChecker+Invalid, 3151 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1178 IncrementalHoareTripleChecker+Valid, 1973 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.5s IncrementalHoareTripleChecker+Time [2022-11-03 03:37:17,621 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1661 Valid, 1212 Invalid, 3151 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1178 Valid, 1973 Invalid, 0 Unknown, 0 Unchecked, 1.5s Time] [2022-11-03 03:37:17,621 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 03:37:17,621 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 03:37:17,621 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 03:37:17,622 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 03:37:17,622 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2022-11-03 03:37:17,622 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 03:37:17,622 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 03:37:17,623 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 33 states, 33 states have (on average 4.454545454545454) internal successors, (147), 33 states have internal predecessors, (147), 17 states have call successors, (29), 8 states have call predecessors, (29), 12 states have return successors, (28), 18 states have call predecessors, (28), 16 states have call successors, (28) [2022-11-03 03:37:17,623 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 03:37:17,623 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 03:37:17,626 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 03:37:17,651 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-11-03 03:37:17,834 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-03 03:37:17,836 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 03:37:24,703 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 160 167) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 03:37:24,703 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 160 167) no Hoare annotation was computed. [2022-11-03 03:37:24,703 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 93 99) no Hoare annotation was computed. [2022-11-03 03:37:24,703 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 93 99) the Hoare annotation is: true [2022-11-03 03:37:24,704 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 877 888) the Hoare annotation is: true [2022-11-03 03:37:24,704 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 877 888) no Hoare annotation was computed. [2022-11-03 03:37:24,704 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 279 308) no Hoare annotation was computed. [2022-11-03 03:37:24,704 INFO L902 garLoopResultBuilder]: At program point L289-2(lines 289 303) the Hoare annotation is: true [2022-11-03 03:37:24,704 INFO L902 garLoopResultBuilder]: At program point L285(line 285) the Hoare annotation is: true [2022-11-03 03:37:24,705 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 279 308) the Hoare annotation is: true [2022-11-03 03:37:24,705 INFO L899 garLoopResultBuilder]: For program point L285-1(line 285) no Hoare annotation was computed. [2022-11-03 03:37:24,705 INFO L902 garLoopResultBuilder]: At program point L304(lines 279 308) the Hoare annotation is: true [2022-11-03 03:37:24,705 INFO L899 garLoopResultBuilder]: For program point L300(line 300) no Hoare annotation was computed. [2022-11-03 03:37:24,705 INFO L899 garLoopResultBuilder]: For program point L293(lines 293 297) no Hoare annotation was computed. [2022-11-03 03:37:24,705 INFO L902 garLoopResultBuilder]: At program point L293-1(lines 293 297) the Hoare annotation is: true [2022-11-03 03:37:24,705 INFO L895 garLoopResultBuilder]: At program point L977(line 977) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (= 0 ~systemActive~0))) (let ((.cse2 (not .cse5)) (.cse6 (and .cse1 (= ~pumpRunning~0 1))) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 .cse1 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse2 (and .cse3 (or .cse1 (= ~waterLevel~0 1)))) (or (not (<= |old(~waterLevel~0)| 1)) .cse4 .cse5 .cse6 .cse7) (or .cse4 (not (= |old(~waterLevel~0)| 2)) .cse5 .cse6) (or .cse0 (and .cse3 .cse1) .cse5 .cse8) (or .cse0 .cse5 .cse9 .cse7 .cse8) (or .cse4 .cse5 .cse9 .cse7 .cse8)))) [2022-11-03 03:37:24,707 INFO L895 garLoopResultBuilder]: At program point L977-1(line 977) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (and .cse4 (<= 1 |timeShift___utac_acc__Specification5_spec__2_#t~ret51#1|) (= ~pumpRunning~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3))) (or .cse3 (not (< 1 |old(~waterLevel~0)|)) .cse4 (not (<= |old(~waterLevel~0)| 2))) (or .cse3 (not .cse2) (and .cse5 (or .cse4 (= ~waterLevel~0 1)))) (or .cse3 .cse5 .cse6) (or .cse0 .cse1 .cse6 .cse2) (or (not (<= |old(~waterLevel~0)| 1)) .cse3 (and .cse5 .cse4) .cse2)))) [2022-11-03 03:37:24,707 INFO L899 garLoopResultBuilder]: For program point L73-2(lines 69 91) no Hoare annotation was computed. [2022-11-03 03:37:24,707 INFO L899 garLoopResultBuilder]: For program point L135(lines 135 143) no Hoare annotation was computed. [2022-11-03 03:37:24,708 INFO L895 garLoopResultBuilder]: At program point L131(lines 131 148) the Hoare annotation is: (let ((.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (= ~pumpRunning~0 1)) (.cse7 (and (= ~pumpRunning~0 0) .cse2)) (.cse8 (not (= |old(~waterLevel~0)| 2))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4) (not (<= |old(~waterLevel~0)| 0)) .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse6 .cse7) (or (not (= |old(~waterLevel~0)| 1)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse3 .cse4) .cse0 .cse1 .cse5) (or .cse0 (and (= ~waterLevel~0 1) .cse3 .cse4) .cse8 .cse1) (or .cse6 .cse7 .cse8) (or .cse6 (not .cse1))))) [2022-11-03 03:37:24,708 INFO L899 garLoopResultBuilder]: For program point L994(lines 994 1004) no Hoare annotation was computed. [2022-11-03 03:37:24,708 INFO L899 garLoopResultBuilder]: For program point L990(lines 990 1007) no Hoare annotation was computed. [2022-11-03 03:37:24,708 INFO L895 garLoopResultBuilder]: At program point L990-1(lines 982 1010) the Hoare annotation is: (let ((.cse8 (not (= |old(~waterLevel~0)| 2))) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| ~waterLevel~0)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (= ~pumpRunning~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (= 0 ~systemActive~0)) (.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse11 (not (= |old(~waterLevel~0)| 1))) (.cse4 (= ~waterLevel~0 1))) (and (or .cse0 .cse1 (not .cse2)) (or (and .cse3 .cse4 .cse5 .cse6) .cse7 (and .cse1 .cse3 .cse4 .cse5) .cse8 .cse2) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and .cse1 .cse3 .cse9) .cse2) (or .cse0 .cse1 .cse8 .cse6) (or (and .cse3 .cse9 .cse5 .cse6) .cse7 (and .cse1 .cse3 .cse9 .cse5) .cse2 (not (<= |old(~waterLevel~0)| 0)) .cse10) (or (and .cse9 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) .cse0 (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2))) (let ((.cse12 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse13 (< 0 |old(~waterLevel~0)|))) (or .cse11 (and .cse1 .cse12 .cse13 .cse3 .cse5) (and .cse12 .cse13 .cse3 .cse5 .cse6) .cse7 .cse2 .cse10)) (or .cse0 .cse11 .cse4))) [2022-11-03 03:37:24,709 INFO L899 garLoopResultBuilder]: For program point L995(lines 995 1001) no Hoare annotation was computed. [2022-11-03 03:37:24,709 INFO L895 garLoopResultBuilder]: At program point L958(line 958) the Hoare annotation is: (let ((.cse1 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1) (or .cse2 .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse1) (or .cse2 (not (= |old(~waterLevel~0)| 2)) .cse3) (or .cse0 (not .cse3)))) [2022-11-03 03:37:24,709 INFO L895 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2)) .cse4) (or (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse4 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 (not .cse4)))) [2022-11-03 03:37:24,709 INFO L895 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2)) .cse4) (or (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse4 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 (not .cse4)))) [2022-11-03 03:37:24,710 INFO L895 garLoopResultBuilder]: At program point L992(line 992) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| ~waterLevel~0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (= 0 ~systemActive~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~waterLevel~0 1))) (and (or .cse0 .cse1 (not .cse2)) (or (and .cse3 .cse4 .cse5 .cse6) .cse7 (and .cse1 .cse3 .cse4 .cse5) (not (= |old(~waterLevel~0)| 2)) .cse2) (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (let ((.cse8 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse10))) (or (not (<= |old(~waterLevel~0)| 1)) (and (<= ~waterLevel~0 0) .cse3 (or .cse8 .cse9) .cse5 .cse6) .cse7 (and .cse1 .cse3 (or (and (not .cse10) .cse9) .cse8) .cse5) .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|))))) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2))) (or .cse0 (and .cse1 .cse3 .cse9) .cse2 (not (< |old(~waterLevel~0)| 3))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse4))) [2022-11-03 03:37:24,710 INFO L899 garLoopResultBuilder]: For program point L992-1(line 992) no Hoare annotation was computed. [2022-11-03 03:37:24,710 INFO L895 garLoopResultBuilder]: At program point L146(line 146) the Hoare annotation is: (let ((.cse1 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= 0 ~systemActive~0))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1) (or .cse2 .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3))) (or .cse0 .cse1 .cse4) (or .cse2 .cse4 .cse3) (or .cse0 (not .cse3)))) [2022-11-03 03:37:24,710 INFO L895 garLoopResultBuilder]: At program point L146-1(lines 127 151) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= 0 ~systemActive~0))) (and (let ((.cse1 (= ~waterLevel~0 1))) (or .cse0 (and .cse1 .cse2 .cse3) (not (= |old(~waterLevel~0)| 2)) .cse4 (and .cse5 .cse1 .cse2))) (or (and (= 2 ~waterLevel~0) .cse6 .cse3) .cse7 (and .cse5 .cse6) (not (< |old(~waterLevel~0)| 3))) (let ((.cse8 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse9 (< 0 |old(~waterLevel~0)|))) (or (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse5 .cse8 .cse9 .cse2) (and .cse8 .cse9 .cse2 .cse3) .cse4 .cse10)) (or .cse0 (and .cse5 .cse6 .cse2) .cse4 (and .cse6 .cse2 .cse3) (not (<= |old(~waterLevel~0)| 0)) .cse10) (or .cse7 (not .cse4)))) [2022-11-03 03:37:24,710 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 66 92) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (= 0 ~systemActive~0))) (let ((.cse2 (not .cse5)) (.cse6 (and .cse1 (= ~pumpRunning~0 1))) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse8 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 .cse1 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse2 (and .cse3 (or .cse1 (= ~waterLevel~0 1)))) (or (not (<= |old(~waterLevel~0)| 1)) .cse4 .cse5 .cse6 .cse7) (or .cse4 (not (= |old(~waterLevel~0)| 2)) .cse5 .cse6) (or .cse0 (and .cse3 .cse1) .cse5 .cse8) (or .cse0 .cse5 .cse9 .cse7 .cse8) (or .cse4 .cse5 .cse9 .cse7 .cse8)))) [2022-11-03 03:37:24,710 INFO L895 garLoopResultBuilder]: At program point L80-1(lines 80 86) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (= 0 ~systemActive~0)) (.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse11 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1))) (and (or .cse0 (and .cse1 .cse2 .cse3) (not (= |old(~waterLevel~0)| 2)) .cse4 (and .cse5 .cse1 .cse2)) (or .cse6 .cse5 (not .cse4)) (or .cse6 (not (< 1 |old(~waterLevel~0)|)) .cse7 (not (<= |old(~waterLevel~0)| 2))) (or (and (= 2 ~waterLevel~0) .cse7 .cse3) .cse6 (and .cse5 .cse7) .cse4 (not (< |old(~waterLevel~0)| 3))) (let ((.cse9 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse10 (< 0 |old(~waterLevel~0)|))) (or .cse8 .cse0 (and .cse5 .cse9 .cse10 .cse2) (and .cse9 .cse10 .cse2 .cse3) .cse4 .cse11)) (or .cse0 (and .cse5 .cse7 .cse2) .cse4 (and .cse7 .cse2 .cse3) (not (<= |old(~waterLevel~0)| 0)) .cse11) (or .cse6 .cse8 .cse1))) [2022-11-03 03:37:24,711 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 92) no Hoare annotation was computed. [2022-11-03 03:37:24,711 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 958) no Hoare annotation was computed. [2022-11-03 03:37:24,711 INFO L895 garLoopResultBuilder]: At program point L440(lines 391 441) the Hoare annotation is: false [2022-11-03 03:37:24,711 INFO L899 garLoopResultBuilder]: For program point L428(lines 428 434) no Hoare annotation was computed. [2022-11-03 03:37:24,711 INFO L895 garLoopResultBuilder]: At program point L428-2(lines 422 435) the Hoare annotation is: (let ((.cse6 (= 0 ~systemActive~0))) (let ((.cse0 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse5 (< ~waterLevel~0 3)) (.cse2 (not .cse6)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse0 .cse1 .cse5) (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) .cse5 .cse2 .cse3) (and .cse4 .cse1 .cse6)))) [2022-11-03 03:37:24,711 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 03:37:24,711 INFO L899 garLoopResultBuilder]: For program point L412(lines 412 418) no Hoare annotation was computed. [2022-11-03 03:37:24,711 INFO L899 garLoopResultBuilder]: For program point L412-1(lines 412 418) no Hoare annotation was computed. [2022-11-03 03:37:24,711 INFO L895 garLoopResultBuilder]: At program point L437(lines 392 439) the Hoare annotation is: (let ((.cse6 (= 0 ~systemActive~0))) (let ((.cse0 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse5 (< ~waterLevel~0 3)) (.cse2 (not .cse6)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse0 .cse1 .cse5) (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) .cse5 .cse2 .cse3) (and .cse4 .cse1 .cse6)))) [2022-11-03 03:37:24,712 INFO L895 garLoopResultBuilder]: At program point L404(line 404) the Hoare annotation is: (let ((.cse6 (= 0 ~systemActive~0))) (let ((.cse0 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse5 (< ~waterLevel~0 3)) (.cse2 (not .cse6)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse0 .cse1 .cse5) (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) .cse5 .cse2 .cse3) (and .cse4 .cse1 .cse6)))) [2022-11-03 03:37:24,712 INFO L895 garLoopResultBuilder]: At program point L268(line 268) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-11-03 03:37:24,712 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 03:37:24,712 INFO L895 garLoopResultBuilder]: At program point L368(lines 368 375) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~4#1| 1) (= |ULTIMATE.start_main_~tmp~4#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-03 03:37:24,712 INFO L902 garLoopResultBuilder]: At program point L368-2(lines 368 375) the Hoare annotation is: true [2022-11-03 03:37:24,712 INFO L899 garLoopResultBuilder]: For program point L393(lines 392 439) no Hoare annotation was computed. [2022-11-03 03:37:24,712 INFO L899 garLoopResultBuilder]: For program point L422(lines 422 435) no Hoare annotation was computed. [2022-11-03 03:37:24,712 INFO L895 garLoopResultBuilder]: At program point L414(line 414) the Hoare annotation is: (let ((.cse6 (= 0 ~systemActive~0))) (let ((.cse0 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse5 (< ~waterLevel~0 3)) (.cse2 (not .cse6)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse0 .cse1 .cse5) (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) .cse5 .cse2 .cse3) (and .cse4 .cse1 .cse6)))) [2022-11-03 03:37:24,712 INFO L902 garLoopResultBuilder]: At program point L443(lines 382 447) the Hoare annotation is: true [2022-11-03 03:37:24,712 INFO L899 garLoopResultBuilder]: For program point L402(lines 402 408) no Hoare annotation was computed. [2022-11-03 03:37:24,712 INFO L899 garLoopResultBuilder]: For program point L402-1(lines 402 408) no Hoare annotation was computed. [2022-11-03 03:37:24,714 INFO L899 garLoopResultBuilder]: For program point L266(lines 266 272) no Hoare annotation was computed. [2022-11-03 03:37:24,714 INFO L895 garLoopResultBuilder]: At program point L266-1(lines 266 272) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-03 03:37:24,714 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 101 125) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 03:37:24,714 INFO L895 garLoopResultBuilder]: At program point L120(line 120) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 03:37:24,714 INFO L899 garLoopResultBuilder]: For program point L120-1(lines 101 125) no Hoare annotation was computed. [2022-11-03 03:37:24,714 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 101 125) no Hoare annotation was computed. [2022-11-03 03:37:24,715 INFO L895 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2) (or .cse3 .cse4 (not (= 2 ~waterLevel~0)) .cse1) (or .cse3 (and .cse4 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) (not (<= ~waterLevel~0 1)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2))) [2022-11-03 03:37:24,715 INFO L895 garLoopResultBuilder]: At program point L109(lines 109 117) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2) (or .cse3 .cse4 (not (= 2 ~waterLevel~0)) .cse1) (or .cse3 (and .cse4 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) (not (<= ~waterLevel~0 1)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2))) [2022-11-03 03:37:24,715 INFO L895 garLoopResultBuilder]: At program point L105(lines 105 122) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-03 03:37:24,715 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 865 876) no Hoare annotation was computed. [2022-11-03 03:37:24,715 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 865 876) the Hoare annotation is: (let ((.cse1 (not (= |old(~waterLevel~0)| 2))) (.cse4 (not (= ~pumpRunning~0 0))) (.cse0 (not (= ~pumpRunning~0 1))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 .cse2 .cse3) (or (not (<= |old(~waterLevel~0)| 1)) .cse4 .cse2 .cse3) (or .cse4 .cse2 (= ~waterLevel~0 1) (not .cse3)) (or .cse0 .cse2 .cse3 (not (<= 1 ~switchedOnBeforeTS~0)) (not (< |old(~waterLevel~0)| 3))))) [2022-11-03 03:37:24,715 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 179 187) no Hoare annotation was computed. [2022-11-03 03:37:24,716 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 179 187) the Hoare annotation is: true [2022-11-03 03:37:24,719 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 03:37:24,720 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 03:37:24,765 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 03:37:24 BoogieIcfgContainer [2022-11-03 03:37:24,765 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 03:37:24,766 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 03:37:24,766 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 03:37:24,766 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 03:37:24,767 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 03:36:20" (3/4) ... [2022-11-03 03:37:24,770 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 03:37:24,776 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-03 03:37:24,776 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 03:37:24,776 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 03:37:24,776 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 03:37:24,776 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 03:37:24,777 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 03:37:24,777 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 03:37:24,777 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-03 03:37:24,783 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 77 nodes and edges [2022-11-03 03:37:24,784 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 27 nodes and edges [2022-11-03 03:37:24,785 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-03 03:37:24,785 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 03:37:24,786 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 03:37:24,786 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:37:24,787 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 03:37:24,812 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1)))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 2))) && (((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || 0 == systemActive) [2022-11-03 03:37:24,813 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) < 3))) && (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 1) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) [2022-11-03 03:37:24,813 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((((((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel)) || 0 == systemActive)) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 2)) || pumpRunning == 1)) && ((((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((\old(waterLevel) == waterLevel && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS)) || ((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) [2022-11-03 03:37:24,814 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(pumpRunning) == 1) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS))) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel))) && ((((!(\old(waterLevel) == 1) || ((\old(waterLevel) == waterLevel + 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:37:24,814 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 1) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 1) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:37:24,814 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) < 3))) && (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 1) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-03 03:37:24,814 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(waterLevel <= 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || 0 == systemActive) || !(waterLevel < 3))) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2022-11-03 03:37:24,816 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(waterLevel <= 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 == waterLevel)) || 0 == systemActive)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && tmp == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) [2022-11-03 03:37:24,842 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 03:37:24,843 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 03:37:24,843 INFO L158 Benchmark]: Toolchain (without parser) took 65820.34ms. Allocated memory was 102.8MB in the beginning and 597.7MB in the end (delta: 494.9MB). Free memory was 61.0MB in the beginning and 472.6MB in the end (delta: -411.6MB). Peak memory consumption was 82.2MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,844 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 102.8MB. Free memory was 78.7MB in the beginning and 78.6MB in the end (delta: 91.0kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:37:24,844 INFO L158 Benchmark]: CACSL2BoogieTranslator took 539.02ms. Allocated memory is still 102.8MB. Free memory was 60.8MB in the beginning and 69.4MB in the end (delta: -8.6MB). Peak memory consumption was 6.4MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,844 INFO L158 Benchmark]: Boogie Procedure Inliner took 48.84ms. Allocated memory is still 102.8MB. Free memory was 69.4MB in the beginning and 67.0MB in the end (delta: 2.4MB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 03:37:24,845 INFO L158 Benchmark]: Boogie Preprocessor took 29.75ms. Allocated memory is still 102.8MB. Free memory was 67.0MB in the beginning and 65.0MB in the end (delta: 2.0MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,845 INFO L158 Benchmark]: RCFGBuilder took 822.82ms. Allocated memory was 102.8MB in the beginning and 125.8MB in the end (delta: 23.1MB). Free memory was 65.0MB in the beginning and 94.9MB in the end (delta: -29.9MB). Peak memory consumption was 27.9MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,845 INFO L158 Benchmark]: TraceAbstraction took 64294.35ms. Allocated memory was 125.8MB in the beginning and 597.7MB in the end (delta: 471.9MB). Free memory was 94.2MB in the beginning and 478.9MB in the end (delta: -384.7MB). Peak memory consumption was 360.4MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,846 INFO L158 Benchmark]: Witness Printer took 77.02ms. Allocated memory is still 597.7MB. Free memory was 478.9MB in the beginning and 472.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-03 03:37:24,848 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 102.8MB. Free memory was 78.7MB in the beginning and 78.6MB in the end (delta: 91.0kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 539.02ms. Allocated memory is still 102.8MB. Free memory was 60.8MB in the beginning and 69.4MB in the end (delta: -8.6MB). Peak memory consumption was 6.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 48.84ms. Allocated memory is still 102.8MB. Free memory was 69.4MB in the beginning and 67.0MB in the end (delta: 2.4MB). There was no memory consumed. Max. memory is 16.1GB. * Boogie Preprocessor took 29.75ms. Allocated memory is still 102.8MB. Free memory was 67.0MB in the beginning and 65.0MB in the end (delta: 2.0MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * RCFGBuilder took 822.82ms. Allocated memory was 102.8MB in the beginning and 125.8MB in the end (delta: 23.1MB). Free memory was 65.0MB in the beginning and 94.9MB in the end (delta: -29.9MB). Peak memory consumption was 27.9MB. Max. memory is 16.1GB. * TraceAbstraction took 64294.35ms. Allocated memory was 125.8MB in the beginning and 597.7MB in the end (delta: 471.9MB). Free memory was 94.2MB in the beginning and 478.9MB in the end (delta: -384.7MB). Peak memory consumption was 360.4MB. Max. memory is 16.1GB. * Witness Printer took 77.02ms. Allocated memory is still 597.7MB. Free memory was 478.9MB in the beginning and 472.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 958]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 64.2s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 7.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 6.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3048 SdHoareTripleChecker+Valid, 3.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3024 mSDsluCounter, 4047 SdHoareTripleChecker+Invalid, 3.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3587 mSDsCounter, 1828 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4254 IncrementalHoareTripleChecker+Invalid, 6082 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1828 mSolverCounterUnsat, 952 mSDtfsCounter, 4254 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1018 GetRequests, 734 SyntacticMatches, 9 SemanticMatches, 275 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7190 ImplicationChecksByTransitivity, 22.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=347occurred in iteration=6, InterpolantAutomatonStates: 146, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 315 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 1316 PreInvPairs, 1534 NumberOfFragments, 2195 HoareAnnotationTreeSize, 1316 FomulaSimplifications, 4968 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 38 FomulaSimplificationsInter, 25702 FormulaSimplificationTreeSizeReductionInter, 6.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 5.2s InterpolantComputationTime, 838 NumberOfCodeBlocks, 838 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1062 ConstructedInterpolants, 0 QuantifiedInterpolants, 3040 SizeOfPredicates, 26 NumberOfNonLiveVariables, 1955 ConjunctsInSsa, 60 ConjunctsInUnsatCore, 18 InterpolantComputations, 8 PerfectInterpolantSequences, 533/615 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 105]: Loop Invariant Derived loop invariant: (((((!(waterLevel <= 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || 0 == systemActive) || !(waterLevel < 3))) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: 131]: Loop Invariant Derived loop invariant: ((((((((!(\old(pumpRunning) == 1) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS))) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel))) && ((((!(\old(waterLevel) == 1) || ((\old(waterLevel) == waterLevel + 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && ((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 2))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: ((((((2 == waterLevel && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) && pumpRunning == 1) || (((pumpRunning == 0 && tmp == 1) && splverifierCounter == 0) && waterLevel < 3)) || (((((tmp == 1 && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && !(0 == systemActive)) && pumpRunning == 1)) || ((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive) - InvariantResult [Line: 279]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == 1) && tmp == systemActive) && waterLevel == 1 - InvariantResult [Line: 80]: Loop Invariant Derived loop invariant: (((((((((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) < 3))) && (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 1) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 982]: Loop Invariant Derived loop invariant: ((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((((((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel)) || 0 == systemActive)) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 2)) || pumpRunning == 1)) && ((((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((\old(waterLevel) == waterLevel && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) == 1) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS)) || ((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 1) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) < 3))) && (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 1)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS)) || (((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS)))) && (((((!(\old(pumpRunning) == 1) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS)) || 0 == systemActive) || ((\old(waterLevel) == waterLevel && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 382]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 289]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 958]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 1) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 1) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: (((((!(waterLevel <= 0) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) && (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 == waterLevel)) || 0 == systemActive)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && tmp == 0)) || !(waterLevel <= 1)) || 0 == systemActive)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= switchedOnBeforeTS)) - InvariantResult [Line: 266]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: ((((((((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1)))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(\old(waterLevel) == 2))) && (((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || 0 == systemActive)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || 0 == systemActive) - InvariantResult [Line: 391]: Loop Invariant Derived loop invariant: 0 RESULT: Ultimate proved your program to be correct! [2022-11-03 03:37:24,910 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5d558c7e-a5a9-4698-8833-79cf7714e855/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE