./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 5e519f3a Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash db9cad3d4bb6f197e1ca94da7e6c4fb3038f74aed96fd168a277cfa6f57caad2 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-5e519f3 [2022-11-03 02:53:22,747 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-03 02:53:22,748 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-03 02:53:22,790 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-03 02:53:22,791 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-03 02:53:22,796 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-03 02:53:22,798 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-03 02:53:22,801 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-03 02:53:22,806 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-03 02:53:22,808 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-03 02:53:22,809 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-03 02:53:22,812 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-03 02:53:22,813 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-03 02:53:22,817 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-03 02:53:22,819 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-03 02:53:22,821 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-03 02:53:22,823 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-03 02:53:22,829 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-03 02:53:22,831 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-03 02:53:22,833 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-03 02:53:22,837 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-03 02:53:22,839 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-03 02:53:22,840 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-03 02:53:22,842 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-03 02:53:22,847 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-03 02:53:22,849 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-03 02:53:22,850 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-03 02:53:22,852 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-03 02:53:22,852 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-03 02:53:22,853 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-03 02:53:22,854 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-03 02:53:22,855 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-03 02:53:22,857 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-03 02:53:22,859 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-03 02:53:22,860 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-03 02:53:22,860 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-03 02:53:22,861 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-03 02:53:22,861 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-03 02:53:22,862 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-03 02:53:22,863 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-03 02:53:22,863 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-03 02:53:22,864 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-03 02:53:22,915 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-03 02:53:22,915 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-03 02:53:22,916 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-03 02:53:22,916 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-03 02:53:22,917 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-03 02:53:22,917 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-03 02:53:22,918 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-03 02:53:22,918 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-03 02:53:22,918 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-03 02:53:22,918 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-03 02:53:22,919 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-03 02:53:22,920 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-03 02:53:22,920 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-03 02:53:22,920 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-03 02:53:22,920 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-03 02:53:22,921 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-03 02:53:22,921 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-03 02:53:22,921 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-03 02:53:22,922 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-03 02:53:22,922 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-03 02:53:22,923 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-03 02:53:22,923 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-03 02:53:22,923 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-03 02:53:22,923 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-03 02:53:22,923 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-03 02:53:22,924 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-03 02:53:22,924 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-03 02:53:22,924 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-03 02:53:22,924 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-03 02:53:22,925 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-03 02:53:22,925 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-03 02:53:22,925 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-03 02:53:22,926 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 02:53:22,926 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-03 02:53:22,926 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-03 02:53:22,926 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-03 02:53:22,927 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-03 02:53:22,927 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-03 02:53:22,927 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-03 02:53:22,927 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-03 02:53:22,927 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-03 02:53:22,928 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> db9cad3d4bb6f197e1ca94da7e6c4fb3038f74aed96fd168a277cfa6f57caad2 [2022-11-03 02:53:23,178 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-03 02:53:23,210 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-03 02:53:23,212 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-03 02:53:23,238 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-03 02:53:23,241 INFO L275 PluginConnector]: CDTParser initialized [2022-11-03 02:53:23,243 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/../../sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c [2022-11-03 02:53:23,321 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/data/aaa4d3776/44dd840f20544a2daa4b1c34ff2daa39/FLAG9b47de088 [2022-11-03 02:53:23,909 INFO L306 CDTParser]: Found 1 translation units. [2022-11-03 02:53:23,909 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c [2022-11-03 02:53:23,935 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/data/aaa4d3776/44dd840f20544a2daa4b1c34ff2daa39/FLAG9b47de088 [2022-11-03 02:53:24,192 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/data/aaa4d3776/44dd840f20544a2daa4b1c34ff2daa39 [2022-11-03 02:53:24,195 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-03 02:53:24,196 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-03 02:53:24,198 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-03 02:53:24,198 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-03 02:53:24,204 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-03 02:53:24,205 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,206 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@6cdb83b6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24, skipping insertion in model container [2022-11-03 02:53:24,207 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,215 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-03 02:53:24,286 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-03 02:53:24,582 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c[14935,14948] [2022-11-03 02:53:24,607 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 02:53:24,617 INFO L203 MainTranslator]: Completed pre-run [2022-11-03 02:53:24,696 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/sv-benchmarks/c/product-lines/minepump_spec5_product58.cil.c[14935,14948] [2022-11-03 02:53:24,714 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-03 02:53:24,747 INFO L208 MainTranslator]: Completed translation [2022-11-03 02:53:24,748 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24 WrapperNode [2022-11-03 02:53:24,748 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-03 02:53:24,750 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-03 02:53:24,750 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-03 02:53:24,750 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-03 02:53:24,759 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,785 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,829 INFO L138 Inliner]: procedures = 59, calls = 160, calls flagged for inlining = 28, calls inlined = 25, statements flattened = 288 [2022-11-03 02:53:24,830 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-03 02:53:24,836 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-03 02:53:24,837 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-03 02:53:24,837 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-03 02:53:24,847 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,848 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,862 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,862 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,867 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,872 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,873 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,885 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,888 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-03 02:53:24,888 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-03 02:53:24,889 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-03 02:53:24,889 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-03 02:53:24,902 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (1/1) ... [2022-11-03 02:53:24,907 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-03 02:53:24,918 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:53:24,931 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-03 02:53:24,945 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-03 02:53:24,976 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-03 02:53:24,977 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-03 02:53:24,977 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-03 02:53:24,977 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-03 02:53:24,977 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-03 02:53:24,977 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-03 02:53:24,977 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-03 02:53:24,977 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 02:53:24,977 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 02:53:24,978 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-03 02:53:24,978 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-03 02:53:24,978 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-03 02:53:24,978 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-03 02:53:24,978 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-03 02:53:24,978 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-03 02:53:24,979 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-03 02:53:24,979 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-03 02:53:24,979 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-03 02:53:25,063 INFO L235 CfgBuilder]: Building ICFG [2022-11-03 02:53:25,065 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-03 02:53:25,456 INFO L276 CfgBuilder]: Performing block encoding [2022-11-03 02:53:25,682 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-03 02:53:25,682 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-03 02:53:25,685 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:53:25 BoogieIcfgContainer [2022-11-03 02:53:25,685 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-03 02:53:25,690 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-03 02:53:25,690 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-03 02:53:25,694 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-03 02:53:25,694 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 03.11 02:53:24" (1/3) ... [2022-11-03 02:53:25,695 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@66e02964 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 02:53:25, skipping insertion in model container [2022-11-03 02:53:25,695 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 03.11 02:53:24" (2/3) ... [2022-11-03 02:53:25,696 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@66e02964 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 03.11 02:53:25, skipping insertion in model container [2022-11-03 02:53:25,696 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:53:25" (3/3) ... [2022-11-03 02:53:25,698 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product58.cil.c [2022-11-03 02:53:25,718 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-03 02:53:25,718 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-03 02:53:25,797 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-03 02:53:25,819 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@ff24519, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-03 02:53:25,819 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-03 02:53:25,828 INFO L276 IsEmpty]: Start isEmpty. Operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-03 02:53:25,839 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-03 02:53:25,839 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:25,840 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:25,841 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:25,848 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:25,849 INFO L85 PathProgramCache]: Analyzing trace with hash 51422514, now seen corresponding path program 1 times [2022-11-03 02:53:25,859 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:25,860 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [978981914] [2022-11-03 02:53:25,860 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:25,861 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:26,052 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:26,204 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:53:26,205 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:26,205 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [978981914] [2022-11-03 02:53:26,207 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [978981914] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:26,207 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:26,207 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-03 02:53:26,209 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1403183381] [2022-11-03 02:53:26,209 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:26,214 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-03 02:53:26,215 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:26,253 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-03 02:53:26,255 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 02:53:26,257 INFO L87 Difference]: Start difference. First operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:26,378 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:26,378 INFO L93 Difference]: Finished difference Result 114 states and 155 transitions. [2022-11-03 02:53:26,380 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-03 02:53:26,382 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-03 02:53:26,382 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:26,392 INFO L225 Difference]: With dead ends: 114 [2022-11-03 02:53:26,392 INFO L226 Difference]: Without dead ends: 53 [2022-11-03 02:53:26,397 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-03 02:53:26,401 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 57 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:26,405 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 57 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 02:53:26,422 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-03 02:53:26,455 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-03 02:53:26,456 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3235294117647058) internal successors, (45), 41 states have internal predecessors, (45), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-03 02:53:26,463 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 68 transitions. [2022-11-03 02:53:26,464 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 68 transitions. Word has length 21 [2022-11-03 02:53:26,465 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:26,465 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 68 transitions. [2022-11-03 02:53:26,467 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:26,467 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 68 transitions. [2022-11-03 02:53:26,472 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-03 02:53:26,472 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:26,473 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:26,474 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-03 02:53:26,475 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:26,476 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:26,476 INFO L85 PathProgramCache]: Analyzing trace with hash 829025429, now seen corresponding path program 1 times [2022-11-03 02:53:26,476 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:26,476 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1142014099] [2022-11-03 02:53:26,477 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:26,477 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:26,526 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:26,649 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:53:26,649 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:26,650 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1142014099] [2022-11-03 02:53:26,650 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1142014099] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:26,651 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:26,651 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-03 02:53:26,651 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [140691750] [2022-11-03 02:53:26,651 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:26,653 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-03 02:53:26,654 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:26,655 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-03 02:53:26,656 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:53:26,657 INFO L87 Difference]: Start difference. First operand 53 states and 68 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:26,745 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:26,746 INFO L93 Difference]: Finished difference Result 83 states and 107 transitions. [2022-11-03 02:53:26,749 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-03 02:53:26,750 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-03 02:53:26,750 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:26,751 INFO L225 Difference]: With dead ends: 83 [2022-11-03 02:53:26,751 INFO L226 Difference]: Without dead ends: 45 [2022-11-03 02:53:26,752 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-03 02:53:26,753 INFO L413 NwaCegarLoop]: 43 mSDtfsCounter, 7 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 77 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:26,754 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 77 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 02:53:26,755 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 45 states. [2022-11-03 02:53:26,760 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 45 to 45. [2022-11-03 02:53:26,760 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 45 states, 29 states have (on average 1.3448275862068966) internal successors, (39), 36 states have internal predecessors, (39), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-03 02:53:26,761 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 45 states to 45 states and 57 transitions. [2022-11-03 02:53:26,761 INFO L78 Accepts]: Start accepts. Automaton has 45 states and 57 transitions. Word has length 22 [2022-11-03 02:53:26,762 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:26,762 INFO L495 AbstractCegarLoop]: Abstraction has 45 states and 57 transitions. [2022-11-03 02:53:26,762 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:26,762 INFO L276 IsEmpty]: Start isEmpty. Operand 45 states and 57 transitions. [2022-11-03 02:53:26,763 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-03 02:53:26,763 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:26,764 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:26,764 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-03 02:53:26,764 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:26,765 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:26,765 INFO L85 PathProgramCache]: Analyzing trace with hash 1503144156, now seen corresponding path program 1 times [2022-11-03 02:53:26,765 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:26,765 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1036379656] [2022-11-03 02:53:26,766 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:26,766 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:26,786 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:26,929 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-03 02:53:26,929 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:26,929 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1036379656] [2022-11-03 02:53:26,929 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1036379656] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:26,930 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:26,930 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 02:53:26,930 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [528061300] [2022-11-03 02:53:26,930 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:26,931 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 02:53:26,931 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:26,932 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 02:53:26,932 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-03 02:53:26,932 INFO L87 Difference]: Start difference. First operand 45 states and 57 transitions. Second operand has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:27,119 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:27,119 INFO L93 Difference]: Finished difference Result 126 states and 165 transitions. [2022-11-03 02:53:27,120 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-03 02:53:27,120 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 24 [2022-11-03 02:53:27,121 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:27,124 INFO L225 Difference]: With dead ends: 126 [2022-11-03 02:53:27,125 INFO L226 Difference]: Without dead ends: 83 [2022-11-03 02:53:27,126 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-03 02:53:27,129 INFO L413 NwaCegarLoop]: 56 mSDtfsCounter, 30 mSDsluCounter, 215 mSDsCounter, 0 mSdLazyCounter, 110 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 31 SdHoareTripleChecker+Valid, 235 SdHoareTripleChecker+Invalid, 117 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 110 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:27,131 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [31 Valid, 235 Invalid, 117 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 110 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-03 02:53:27,133 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 83 states. [2022-11-03 02:53:27,152 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 83 to 79. [2022-11-03 02:53:27,153 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 79 states, 52 states have (on average 1.2692307692307692) internal successors, (66), 59 states have internal predecessors, (66), 14 states have call successors, (14), 12 states have call predecessors, (14), 12 states have return successors, (18), 14 states have call predecessors, (18), 14 states have call successors, (18) [2022-11-03 02:53:27,156 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 79 states to 79 states and 98 transitions. [2022-11-03 02:53:27,156 INFO L78 Accepts]: Start accepts. Automaton has 79 states and 98 transitions. Word has length 24 [2022-11-03 02:53:27,157 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:27,157 INFO L495 AbstractCegarLoop]: Abstraction has 79 states and 98 transitions. [2022-11-03 02:53:27,158 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-03 02:53:27,158 INFO L276 IsEmpty]: Start isEmpty. Operand 79 states and 98 transitions. [2022-11-03 02:53:27,164 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-03 02:53:27,164 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:27,164 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:27,165 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-03 02:53:27,165 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:27,166 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:27,166 INFO L85 PathProgramCache]: Analyzing trace with hash 148799262, now seen corresponding path program 1 times [2022-11-03 02:53:27,166 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:27,167 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1097143029] [2022-11-03 02:53:27,167 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:27,169 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:27,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:27,743 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:53:27,743 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:27,743 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1097143029] [2022-11-03 02:53:27,743 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1097143029] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:27,744 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:27,744 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-03 02:53:27,744 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [131781705] [2022-11-03 02:53:27,744 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:27,745 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-03 02:53:27,745 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:27,745 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-03 02:53:27,745 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-03 02:53:27,746 INFO L87 Difference]: Start difference. First operand 79 states and 98 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 02:53:27,976 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:27,976 INFO L93 Difference]: Finished difference Result 236 states and 293 transitions. [2022-11-03 02:53:27,977 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-03 02:53:27,977 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 32 [2022-11-03 02:53:27,978 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:27,979 INFO L225 Difference]: With dead ends: 236 [2022-11-03 02:53:27,980 INFO L226 Difference]: Without dead ends: 159 [2022-11-03 02:53:27,980 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-03 02:53:27,982 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 100 mSDsluCounter, 141 mSDsCounter, 0 mSdLazyCounter, 126 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 101 SdHoareTripleChecker+Valid, 196 SdHoareTripleChecker+Invalid, 152 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 126 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:27,982 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [101 Valid, 196 Invalid, 152 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 126 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-03 02:53:27,983 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 159 states. [2022-11-03 02:53:28,008 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 159 to 155. [2022-11-03 02:53:28,008 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 155 states, 100 states have (on average 1.24) internal successors, (124), 112 states have internal predecessors, (124), 29 states have call successors, (29), 25 states have call predecessors, (29), 25 states have return successors, (38), 27 states have call predecessors, (38), 29 states have call successors, (38) [2022-11-03 02:53:28,011 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 155 states to 155 states and 191 transitions. [2022-11-03 02:53:28,011 INFO L78 Accepts]: Start accepts. Automaton has 155 states and 191 transitions. Word has length 32 [2022-11-03 02:53:28,011 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:28,012 INFO L495 AbstractCegarLoop]: Abstraction has 155 states and 191 transitions. [2022-11-03 02:53:28,012 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-03 02:53:28,012 INFO L276 IsEmpty]: Start isEmpty. Operand 155 states and 191 transitions. [2022-11-03 02:53:28,013 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-03 02:53:28,013 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:28,014 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:28,014 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-03 02:53:28,014 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:28,014 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:28,015 INFO L85 PathProgramCache]: Analyzing trace with hash 2014061962, now seen corresponding path program 1 times [2022-11-03 02:53:28,015 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:28,015 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [378850309] [2022-11-03 02:53:28,015 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:28,015 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:28,054 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:28,465 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-03 02:53:28,466 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:28,466 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [378850309] [2022-11-03 02:53:28,466 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [378850309] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:28,466 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:28,467 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-03 02:53:28,467 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [997176055] [2022-11-03 02:53:28,467 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:28,467 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-03 02:53:28,468 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:28,468 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-03 02:53:28,468 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-03 02:53:28,468 INFO L87 Difference]: Start difference. First operand 155 states and 191 transitions. Second operand has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 02:53:29,007 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:29,007 INFO L93 Difference]: Finished difference Result 366 states and 464 transitions. [2022-11-03 02:53:29,008 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-03 02:53:29,008 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 35 [2022-11-03 02:53:29,008 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:29,011 INFO L225 Difference]: With dead ends: 366 [2022-11-03 02:53:29,011 INFO L226 Difference]: Without dead ends: 261 [2022-11-03 02:53:29,012 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-03 02:53:29,013 INFO L413 NwaCegarLoop]: 71 mSDtfsCounter, 176 mSDsluCounter, 188 mSDsCounter, 0 mSdLazyCounter, 286 mSolverCounterSat, 76 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 181 SdHoareTripleChecker+Valid, 227 SdHoareTripleChecker+Invalid, 362 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 76 IncrementalHoareTripleChecker+Valid, 286 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:29,014 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [181 Valid, 227 Invalid, 362 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [76 Valid, 286 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-03 02:53:29,015 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 261 states. [2022-11-03 02:53:29,048 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 261 to 231. [2022-11-03 02:53:29,049 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 231 states, 154 states have (on average 1.2532467532467533) internal successors, (193), 171 states have internal predecessors, (193), 40 states have call successors, (40), 31 states have call predecessors, (40), 36 states have return successors, (55), 42 states have call predecessors, (55), 40 states have call successors, (55) [2022-11-03 02:53:29,051 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 231 states to 231 states and 288 transitions. [2022-11-03 02:53:29,051 INFO L78 Accepts]: Start accepts. Automaton has 231 states and 288 transitions. Word has length 35 [2022-11-03 02:53:29,052 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:29,052 INFO L495 AbstractCegarLoop]: Abstraction has 231 states and 288 transitions. [2022-11-03 02:53:29,052 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-03 02:53:29,052 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 288 transitions. [2022-11-03 02:53:29,053 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-03 02:53:29,054 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:29,054 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:29,054 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-03 02:53:29,054 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:29,055 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:29,055 INFO L85 PathProgramCache]: Analyzing trace with hash 2116699212, now seen corresponding path program 1 times [2022-11-03 02:53:29,055 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:29,055 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [960646766] [2022-11-03 02:53:29,055 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:29,056 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:29,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:29,217 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 02:53:29,217 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:29,217 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [960646766] [2022-11-03 02:53:29,217 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [960646766] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-03 02:53:29,217 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-03 02:53:29,218 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-03 02:53:29,218 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2083846001] [2022-11-03 02:53:29,218 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-03 02:53:29,218 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-03 02:53:29,219 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:29,219 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-03 02:53:29,219 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-03 02:53:29,219 INFO L87 Difference]: Start difference. First operand 231 states and 288 transitions. Second operand has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) [2022-11-03 02:53:29,290 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:29,290 INFO L93 Difference]: Finished difference Result 460 states and 580 transitions. [2022-11-03 02:53:29,291 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-03 02:53:29,291 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) Word has length 52 [2022-11-03 02:53:29,291 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:29,293 INFO L225 Difference]: With dead ends: 460 [2022-11-03 02:53:29,293 INFO L226 Difference]: Without dead ends: 231 [2022-11-03 02:53:29,294 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-03 02:53:29,295 INFO L413 NwaCegarLoop]: 39 mSDtfsCounter, 40 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 41 SdHoareTripleChecker+Valid, 77 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:29,296 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [41 Valid, 77 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-03 02:53:29,297 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 231 states. [2022-11-03 02:53:29,329 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 231 to 231. [2022-11-03 02:53:29,330 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 231 states, 154 states have (on average 1.2207792207792207) internal successors, (188), 171 states have internal predecessors, (188), 40 states have call successors, (40), 31 states have call predecessors, (40), 36 states have return successors, (55), 42 states have call predecessors, (55), 40 states have call successors, (55) [2022-11-03 02:53:29,331 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 231 states to 231 states and 283 transitions. [2022-11-03 02:53:29,332 INFO L78 Accepts]: Start accepts. Automaton has 231 states and 283 transitions. Word has length 52 [2022-11-03 02:53:29,332 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:29,332 INFO L495 AbstractCegarLoop]: Abstraction has 231 states and 283 transitions. [2022-11-03 02:53:29,332 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (7), 2 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 3 states have call successors, (6) [2022-11-03 02:53:29,333 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 283 transitions. [2022-11-03 02:53:29,334 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2022-11-03 02:53:29,334 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:29,335 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:29,335 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-03 02:53:29,335 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:29,335 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:29,335 INFO L85 PathProgramCache]: Analyzing trace with hash -1860818290, now seen corresponding path program 1 times [2022-11-03 02:53:29,336 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:29,336 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [755329537] [2022-11-03 02:53:29,336 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:29,336 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:29,355 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:29,881 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 0 proven. 16 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-03 02:53:29,882 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:29,882 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [755329537] [2022-11-03 02:53:29,882 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [755329537] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 02:53:29,882 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1442338687] [2022-11-03 02:53:29,883 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:29,883 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:53:29,883 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:53:29,886 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 02:53:29,899 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-03 02:53:30,016 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:30,019 INFO L263 TraceCheckSpWp]: Trace formula consists of 466 conjuncts, 22 conjunts are in the unsatisfiable core [2022-11-03 02:53:30,025 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 02:53:30,349 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 26 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-03 02:53:30,350 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 02:53:30,548 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-03 02:53:30,549 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1442338687] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 02:53:30,549 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1290879591] [2022-11-03 02:53:30,577 INFO L159 IcfgInterpreter]: Started Sifa with 36 locations of interest [2022-11-03 02:53:30,577 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 02:53:30,581 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 02:53:30,586 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 02:53:30,587 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 02:53:43,151 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 50 for LOIs [2022-11-03 02:53:43,160 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 57 for LOIs [2022-11-03 02:53:43,381 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 44 for LOIs [2022-11-03 02:53:43,387 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 28 for LOIs [2022-11-03 02:53:43,418 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 02:53:48,630 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '3931#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (= ~head~0.offset 0) (= 1 ~systemActive~0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (<= 2 |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= |old(~switchedOnBeforeTS~0)| 0))' at error location [2022-11-03 02:53:48,630 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 02:53:48,631 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 02:53:48,631 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 14 [2022-11-03 02:53:48,631 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [476044960] [2022-11-03 02:53:48,631 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 02:53:48,632 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-11-03 02:53:48,632 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:53:48,633 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-11-03 02:53:48,633 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=187, Invalid=1453, Unknown=0, NotChecked=0, Total=1640 [2022-11-03 02:53:48,634 INFO L87 Difference]: Start difference. First operand 231 states and 283 transitions. Second operand has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) [2022-11-03 02:53:50,187 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:53:50,188 INFO L93 Difference]: Finished difference Result 662 states and 839 transitions. [2022-11-03 02:53:50,188 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 34 states. [2022-11-03 02:53:50,188 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) Word has length 60 [2022-11-03 02:53:50,190 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:53:50,198 INFO L225 Difference]: With dead ends: 662 [2022-11-03 02:53:50,199 INFO L226 Difference]: Without dead ends: 433 [2022-11-03 02:53:50,202 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 227 GetRequests, 159 SyntacticMatches, 5 SemanticMatches, 63 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1460 ImplicationChecksByTransitivity, 6.0s TimeCoverageRelationStatistics Valid=502, Invalid=3658, Unknown=0, NotChecked=0, Total=4160 [2022-11-03 02:53:50,204 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 443 mSDsluCounter, 331 mSDsCounter, 0 mSdLazyCounter, 756 mSolverCounterSat, 316 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 449 SdHoareTripleChecker+Valid, 330 SdHoareTripleChecker+Invalid, 1072 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 316 IncrementalHoareTripleChecker+Valid, 756 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2022-11-03 02:53:50,205 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [449 Valid, 330 Invalid, 1072 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [316 Valid, 756 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2022-11-03 02:53:50,208 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 433 states. [2022-11-03 02:53:50,258 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 433 to 383. [2022-11-03 02:53:50,259 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 383 states, 255 states have (on average 1.184313725490196) internal successors, (302), 286 states have internal predecessors, (302), 62 states have call successors, (62), 50 states have call predecessors, (62), 65 states have return successors, (105), 66 states have call predecessors, (105), 62 states have call successors, (105) [2022-11-03 02:53:50,262 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 383 states to 383 states and 469 transitions. [2022-11-03 02:53:50,262 INFO L78 Accepts]: Start accepts. Automaton has 383 states and 469 transitions. Word has length 60 [2022-11-03 02:53:50,263 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:53:50,263 INFO L495 AbstractCegarLoop]: Abstraction has 383 states and 469 transitions. [2022-11-03 02:53:50,263 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) [2022-11-03 02:53:50,264 INFO L276 IsEmpty]: Start isEmpty. Operand 383 states and 469 transitions. [2022-11-03 02:53:50,265 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2022-11-03 02:53:50,266 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:53:50,266 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:53:50,302 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-03 02:53:50,479 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:53:50,480 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:53:50,480 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:53:50,480 INFO L85 PathProgramCache]: Analyzing trace with hash -257129915, now seen corresponding path program 1 times [2022-11-03 02:53:50,480 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:53:50,480 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [962207273] [2022-11-03 02:53:50,480 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:50,481 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:53:50,500 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:50,837 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 1 proven. 20 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-03 02:53:50,837 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:53:50,838 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [962207273] [2022-11-03 02:53:50,838 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [962207273] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 02:53:50,838 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1858562280] [2022-11-03 02:53:50,838 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:53:50,838 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:53:50,839 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:53:50,840 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 02:53:50,858 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-03 02:53:50,945 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:53:50,948 INFO L263 TraceCheckSpWp]: Trace formula consists of 458 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-03 02:53:50,951 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 02:53:51,004 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 14 proven. 1 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-03 02:53:51,004 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 02:53:51,089 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 7 proven. 1 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-03 02:53:51,089 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1858562280] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 02:53:51,089 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [354092110] [2022-11-03 02:53:51,092 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-03 02:53:51,092 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 02:53:51,093 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 02:53:51,093 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 02:53:51,093 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 02:54:02,216 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 321 for LOIs [2022-11-03 02:54:02,286 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 59 for LOIs [2022-11-03 02:54:02,525 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 26 for LOIs [2022-11-03 02:54:02,527 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 63 for LOIs [2022-11-03 02:54:02,755 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 37 for LOIs [2022-11-03 02:54:02,758 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 02:54:16,211 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '6052#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (= ~head~0.offset 0) (<= |old(~switchedOnBeforeTS~0)| 2147483647) (= 1 ~systemActive~0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (<= 0 (+ |old(~switchedOnBeforeTS~0)| 2147483648)) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483648)) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2147483648)))' at error location [2022-11-03 02:54:16,212 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 02:54:16,212 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 02:54:16,212 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 6, 6] total 13 [2022-11-03 02:54:16,212 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1832990762] [2022-11-03 02:54:16,212 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 02:54:16,213 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-03 02:54:16,213 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:54:16,214 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-03 02:54:16,217 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=188, Invalid=1534, Unknown=0, NotChecked=0, Total=1722 [2022-11-03 02:54:16,217 INFO L87 Difference]: Start difference. First operand 383 states and 469 transitions. Second operand has 13 states, 11 states have (on average 6.0) internal successors, (66), 11 states have internal predecessors, (66), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) [2022-11-03 02:54:17,229 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:54:17,229 INFO L93 Difference]: Finished difference Result 746 states and 939 transitions. [2022-11-03 02:54:17,229 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 25 states. [2022-11-03 02:54:17,230 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 11 states have (on average 6.0) internal successors, (66), 11 states have internal predecessors, (66), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) Word has length 63 [2022-11-03 02:54:17,230 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:54:17,233 INFO L225 Difference]: With dead ends: 746 [2022-11-03 02:54:17,233 INFO L226 Difference]: Without dead ends: 458 [2022-11-03 02:54:17,235 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 230 GetRequests, 166 SyntacticMatches, 4 SemanticMatches, 60 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1266 ImplicationChecksByTransitivity, 14.0s TimeCoverageRelationStatistics Valid=401, Invalid=3381, Unknown=0, NotChecked=0, Total=3782 [2022-11-03 02:54:17,236 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 285 mSDsluCounter, 350 mSDsCounter, 0 mSdLazyCounter, 546 mSolverCounterSat, 196 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 288 SdHoareTripleChecker+Valid, 350 SdHoareTripleChecker+Invalid, 742 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 196 IncrementalHoareTripleChecker+Valid, 546 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-03 02:54:17,236 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [288 Valid, 350 Invalid, 742 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [196 Valid, 546 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-03 02:54:17,237 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 458 states. [2022-11-03 02:54:17,288 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 458 to 438. [2022-11-03 02:54:17,290 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 438 states, 288 states have (on average 1.1597222222222223) internal successors, (334), 325 states have internal predecessors, (334), 74 states have call successors, (74), 62 states have call predecessors, (74), 75 states have return successors, (122), 75 states have call predecessors, (122), 74 states have call successors, (122) [2022-11-03 02:54:17,292 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 438 states to 438 states and 530 transitions. [2022-11-03 02:54:17,293 INFO L78 Accepts]: Start accepts. Automaton has 438 states and 530 transitions. Word has length 63 [2022-11-03 02:54:17,293 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:54:17,293 INFO L495 AbstractCegarLoop]: Abstraction has 438 states and 530 transitions. [2022-11-03 02:54:17,294 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 11 states have (on average 6.0) internal successors, (66), 11 states have internal predecessors, (66), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) [2022-11-03 02:54:17,294 INFO L276 IsEmpty]: Start isEmpty. Operand 438 states and 530 transitions. [2022-11-03 02:54:17,296 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2022-11-03 02:54:17,296 INFO L187 NwaCegarLoop]: Found error trace [2022-11-03 02:54:17,297 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:54:17,338 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-03 02:54:17,514 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable7 [2022-11-03 02:54:17,514 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-03 02:54:17,515 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-03 02:54:17,515 INFO L85 PathProgramCache]: Analyzing trace with hash 801223230, now seen corresponding path program 1 times [2022-11-03 02:54:17,515 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-03 02:54:17,515 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [426460846] [2022-11-03 02:54:17,515 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:54:17,515 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-03 02:54:17,535 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:54:18,619 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 11 proven. 43 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 02:54:18,619 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-03 02:54:18,619 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [426460846] [2022-11-03 02:54:18,619 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [426460846] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-03 02:54:18,619 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1896647565] [2022-11-03 02:54:18,619 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-03 02:54:18,619 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-03 02:54:18,620 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 [2022-11-03 02:54:18,621 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-03 02:54:18,646 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-03 02:54:18,758 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-03 02:54:18,761 INFO L263 TraceCheckSpWp]: Trace formula consists of 562 conjuncts, 30 conjunts are in the unsatisfiable core [2022-11-03 02:54:18,765 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-03 02:54:19,133 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 55 proven. 15 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-03 02:54:19,133 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-03 02:54:19,656 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 49 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-03 02:54:19,656 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1896647565] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-03 02:54:19,656 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [2068046140] [2022-11-03 02:54:19,658 INFO L159 IcfgInterpreter]: Started Sifa with 37 locations of interest [2022-11-03 02:54:19,659 INFO L166 IcfgInterpreter]: Building call graph [2022-11-03 02:54:19,659 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-03 02:54:19,659 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-03 02:54:19,659 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-03 02:54:29,171 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 324 for LOIs [2022-11-03 02:54:29,287 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 36 for LOIs [2022-11-03 02:54:29,522 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 58 for LOIs [2022-11-03 02:54:29,532 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 28 for LOIs [2022-11-03 02:54:29,555 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-03 02:54:41,468 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '8534#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| |timeShift_getWaterLevel_#res#1|) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (<= 0 |old(~pumpRunning~0)|) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 1) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (<= |old(~pumpRunning~0)| 1) (= |timeShift_getWaterLevel_~retValue_acc~1#1| ~waterLevel~0) (= ~head~0.offset 0) (<= |old(~switchedOnBeforeTS~0)| 2147483647) (= 1 ~systemActive~0) (= |timeShift_getWaterLevel_~retValue_acc~1#1| |timeShift_getWaterLevel_#res#1|) (<= 0 (+ |old(~switchedOnBeforeTS~0)| 2147483648)) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2)) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= |timeShift_getWaterLevel_~retValue_acc~1#1| 2147483647) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| 2147483648)))' at error location [2022-11-03 02:54:41,468 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-03 02:54:41,468 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-03 02:54:41,469 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [19, 11, 11] total 31 [2022-11-03 02:54:41,469 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1664785623] [2022-11-03 02:54:41,469 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-03 02:54:41,470 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 31 states [2022-11-03 02:54:41,470 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-03 02:54:41,470 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 31 interpolants. [2022-11-03 02:54:41,472 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=359, Invalid=3181, Unknown=0, NotChecked=0, Total=3540 [2022-11-03 02:54:41,472 INFO L87 Difference]: Start difference. First operand 438 states and 530 transitions. Second operand has 31 states, 30 states have (on average 4.433333333333334) internal successors, (133), 30 states have internal predecessors, (133), 16 states have call successors, (25), 8 states have call predecessors, (25), 11 states have return successors, (24), 15 states have call predecessors, (24), 15 states have call successors, (24) [2022-11-03 02:54:46,503 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-03 02:54:46,503 INFO L93 Difference]: Finished difference Result 1010 states and 1280 transitions. [2022-11-03 02:54:46,504 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 69 states. [2022-11-03 02:54:46,504 INFO L78 Accepts]: Start accepts. Automaton has has 31 states, 30 states have (on average 4.433333333333334) internal successors, (133), 30 states have internal predecessors, (133), 16 states have call successors, (25), 8 states have call predecessors, (25), 11 states have return successors, (24), 15 states have call predecessors, (24), 15 states have call successors, (24) Word has length 85 [2022-11-03 02:54:46,508 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-03 02:54:46,509 INFO L225 Difference]: With dead ends: 1010 [2022-11-03 02:54:46,509 INFO L226 Difference]: Without dead ends: 0 [2022-11-03 02:54:46,522 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 364 GetRequests, 243 SyntacticMatches, 4 SemanticMatches, 117 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5296 ImplicationChecksByTransitivity, 15.2s TimeCoverageRelationStatistics Valid=1740, Invalid=12302, Unknown=0, NotChecked=0, Total=14042 [2022-11-03 02:54:46,525 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 1118 mSDsluCounter, 939 mSDsCounter, 0 mSdLazyCounter, 2264 mSolverCounterSat, 784 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1126 SdHoareTripleChecker+Valid, 802 SdHoareTripleChecker+Invalid, 3048 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 784 IncrementalHoareTripleChecker+Valid, 2264 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.9s IncrementalHoareTripleChecker+Time [2022-11-03 02:54:46,526 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1126 Valid, 802 Invalid, 3048 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [784 Valid, 2264 Invalid, 0 Unknown, 0 Unchecked, 1.9s Time] [2022-11-03 02:54:46,527 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-03 02:54:46,527 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-03 02:54:46,528 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-03 02:54:46,528 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-03 02:54:46,530 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 85 [2022-11-03 02:54:46,530 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-03 02:54:46,530 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-03 02:54:46,531 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 31 states, 30 states have (on average 4.433333333333334) internal successors, (133), 30 states have internal predecessors, (133), 16 states have call successors, (25), 8 states have call predecessors, (25), 11 states have return successors, (24), 15 states have call predecessors, (24), 15 states have call successors, (24) [2022-11-03 02:54:46,531 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-03 02:54:46,531 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-03 02:54:46,534 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-03 02:54:46,589 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-03 02:54:46,762 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2022-11-03 02:54:46,765 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-03 02:54:53,483 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 790 796) no Hoare annotation was computed. [2022-11-03 02:54:53,484 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 790 796) the Hoare annotation is: true [2022-11-03 02:54:53,484 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: true [2022-11-03 02:54:53,484 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2022-11-03 02:54:53,484 INFO L899 garLoopResultBuilder]: For program point L770-2(lines 766 788) no Hoare annotation was computed. [2022-11-03 02:54:53,485 INFO L895 garLoopResultBuilder]: At program point L832(lines 832 840) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse2 (let ((.cse3 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse3) (= |old(~waterLevel~0)| ~waterLevel~0)) (and .cse4 .cse3))) .cse5) .cse0 .cse1) (or (and .cse2 .cse4 .cse5) .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-03 02:54:53,485 INFO L895 garLoopResultBuilder]: At program point L192(line 192) the Hoare annotation is: (let ((.cse9 (+ ~waterLevel~0 1))) (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (= |old(~waterLevel~0)| .cse9)) (.cse4 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (= ~pumpRunning~0 0)) (.cse1 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| ~waterLevel~0)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or (and .cse0 .cse1 .cse2 .cse3) .cse4 .cse5 (and .cse6 .cse7 .cse1 (= ~waterLevel~0 1)) (not (<= 2 |old(~waterLevel~0)|))) (let ((.cse8 (or (and .cse2 (< 0 |old(~waterLevel~0)|)) .cse10))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (not (<= |old(~waterLevel~0)| 1)) .cse4 (and .cse0 .cse1 (<= ~waterLevel~0 0) .cse8 .cse3) (and .cse6 .cse7 .cse1 .cse8 (or (<= |old(~waterLevel~0)| 0) (<= .cse9 |old(~waterLevel~0)|))) (= |old(~switchedOnBeforeTS~0)| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse4 .cse5 (and .cse7 .cse1 .cse10 .cse3))))) [2022-11-03 02:54:53,485 INFO L899 garLoopResultBuilder]: For program point L192-1(line 192) no Hoare annotation was computed. [2022-11-03 02:54:53,486 INFO L895 garLoopResultBuilder]: At program point L828(lines 828 845) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (= 0 ~systemActive~0)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse0 .cse1 (let ((.cse3 (< 0 |old(~waterLevel~0)|))) (or .cse2 (and (not .cse3) .cse4) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse3)))) .cse5 .cse6) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (and .cse2 .cse4 .cse1) .cse5) (or .cse5 .cse6 (and .cse0 (or (and (not .cse2) (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0)) (and .cse2 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) .cse1) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-03 02:54:53,486 INFO L895 garLoopResultBuilder]: At program point L177(line 177) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4)) (.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse2) (or .cse1 .cse2 .cse3 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse2 .cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or (not (= |old(~pumpRunning~0)| 0)) .cse2 .cse3 (and (not (= ~switchedOnBeforeTS~0 0)) (= ~pumpRunning~0 0) .cse4) (= |old(~switchedOnBeforeTS~0)| 0))))) [2022-11-03 02:54:53,487 INFO L895 garLoopResultBuilder]: At program point L177-1(line 177) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= |timeShift___utac_acc__Specification5_spec__2_#t~ret9#1| ~pumpRunning~0))) (let ((.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1)) (.cse4 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0 .cse1) .cse2 .cse3) (or .cse4 .cse2 .cse3 .cse5 .cse6) (or .cse4 (not (= |old(~waterLevel~0)| 1)) .cse2 .cse5) (or .cse7 .cse2 .cse3 .cse6) (or .cse4 (not (<= |old(~waterLevel~0)| 1)) .cse7 .cse2) (or .cse4 .cse2 .cse3 .cse5 (= |old(~switchedOnBeforeTS~0)| 0))))) [2022-11-03 02:54:53,487 INFO L895 garLoopResultBuilder]: At program point L685(line 685) the Hoare annotation is: (let ((.cse1 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse1 .cse0) (or .cse1 (not (= |old(~pumpRunning~0)| 0)) .cse0))) [2022-11-03 02:54:53,487 INFO L895 garLoopResultBuilder]: At program point L838(line 838) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse2 (let ((.cse3 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse3) (= |old(~waterLevel~0)| ~waterLevel~0)) (and .cse4 .cse3))) .cse5) .cse0 .cse1) (or (and .cse2 .cse4 .cse5) .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-03 02:54:53,487 INFO L899 garLoopResultBuilder]: For program point L194(lines 194 204) no Hoare annotation was computed. [2022-11-03 02:54:53,488 INFO L899 garLoopResultBuilder]: For program point L190(lines 190 207) no Hoare annotation was computed. [2022-11-03 02:54:53,488 INFO L895 garLoopResultBuilder]: At program point L190-1(lines 182 210) the Hoare annotation is: (let ((.cse16 (+ ~waterLevel~0 1))) (let ((.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (= 0 ~systemActive~0)) (.cse12 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse13 (not (= ~switchedOnBeforeTS~0 0))) (.cse8 (= ~pumpRunning~0 0)) (.cse9 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~0#1| ~waterLevel~0)) (.cse5 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse1 (= |old(~waterLevel~0)| .cse16)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse2 (and .cse8 .cse9 .cse10 .cse11)) (let ((.cse14 (or .cse7 .cse10))) (or (and .cse9 .cse10 (or .cse12 (not .cse8))) .cse2 .cse3 (and .cse13 .cse8 .cse9 (= ~waterLevel~0 1) .cse14) (and .cse12 .cse9 .cse1 .cse11 .cse14) .cse4)) (let ((.cse15 (or (and .cse1 (< 0 |old(~waterLevel~0)|)) .cse10))) (or .cse0 .cse6 .cse2 (and .cse12 .cse9 (<= ~waterLevel~0 0) .cse15 .cse11) (and .cse13 .cse8 .cse9 .cse15 (or (<= |old(~waterLevel~0)| 0) (<= .cse16 |old(~waterLevel~0)|))) .cse5))))) [2022-11-03 02:54:53,488 INFO L895 garLoopResultBuilder]: At program point L843(line 843) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) (and .cse1 .cse2 .cse3) .cse4) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 .cse4 (= |old(~switchedOnBeforeTS~0)| 0)) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2 .cse3) .cse4 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-03 02:54:53,489 INFO L895 garLoopResultBuilder]: At program point L843-1(lines 824 848) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= ~switchedOnBeforeTS~0 0))) (.cse9 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (= 0 ~systemActive~0))) (and (let ((.cse1 (let ((.cse7 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse7) .cse8) (and .cse9 .cse7))))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse4 .cse1) .cse5 .cse6 (= |old(~switchedOnBeforeTS~0)| 0))) (or (and .cse0 .cse10 .cse9 .cse2) (and .cse8 (or .cse0 (not .cse4))) .cse5 .cse6 (and .cse3 .cse10 .cse4 .cse9) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse10 (and .cse4 .cse8 .cse2) .cse5))) [2022-11-03 02:54:53,489 INFO L895 garLoopResultBuilder]: At program point L777-1(lines 777 783) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= ~switchedOnBeforeTS~0 0))) (.cse9 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (= 0 ~systemActive~0))) (and (let ((.cse1 (let ((.cse7 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse7) .cse8) (and .cse9 .cse7))))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse4 .cse1) .cse5 .cse6 (= |old(~switchedOnBeforeTS~0)| 0))) (or (and .cse0 .cse10 .cse9 .cse2) (and .cse8 (or .cse0 (not .cse4))) .cse5 .cse6 (and .cse3 .cse10 .cse4 .cse9) (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) .cse10 (and .cse4 .cse8 .cse2) .cse5))) [2022-11-03 02:54:53,489 INFO L899 garLoopResultBuilder]: For program point L195(lines 195 201) no Hoare annotation was computed. [2022-11-03 02:54:53,490 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 763 789) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4)) (.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse2) (or .cse1 .cse2 .cse3 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 .cse2 .cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or (not (= |old(~pumpRunning~0)| 0)) .cse2 .cse3 (and (not (= ~switchedOnBeforeTS~0 0)) (= ~pumpRunning~0 0) .cse4) (= |old(~switchedOnBeforeTS~0)| 0))))) [2022-11-03 02:54:53,490 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 763 789) no Hoare annotation was computed. [2022-11-03 02:54:53,490 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 685) no Hoare annotation was computed. [2022-11-03 02:54:53,490 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 580 609) no Hoare annotation was computed. [2022-11-03 02:54:53,491 INFO L902 garLoopResultBuilder]: At program point L605(lines 580 609) the Hoare annotation is: true [2022-11-03 02:54:53,491 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 580 609) the Hoare annotation is: true [2022-11-03 02:54:53,491 INFO L899 garLoopResultBuilder]: For program point L601(line 601) no Hoare annotation was computed. [2022-11-03 02:54:53,491 INFO L899 garLoopResultBuilder]: For program point L594(lines 594 598) no Hoare annotation was computed. [2022-11-03 02:54:53,491 INFO L902 garLoopResultBuilder]: At program point L594-1(lines 594 598) the Hoare annotation is: true [2022-11-03 02:54:53,491 INFO L902 garLoopResultBuilder]: At program point L590-2(lines 590 604) the Hoare annotation is: true [2022-11-03 02:54:53,492 INFO L902 garLoopResultBuilder]: At program point L586(line 586) the Hoare annotation is: true [2022-11-03 02:54:53,492 INFO L899 garLoopResultBuilder]: For program point L586-1(line 586) no Hoare annotation was computed. [2022-11-03 02:54:53,492 INFO L895 garLoopResultBuilder]: At program point L667(lines 667 674) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= 0 ~systemActive~0))) [2022-11-03 02:54:53,492 INFO L902 garLoopResultBuilder]: At program point L667-2(lines 667 674) the Hoare annotation is: true [2022-11-03 02:54:53,492 INFO L899 garLoopResultBuilder]: For program point L721(lines 721 727) no Hoare annotation was computed. [2022-11-03 02:54:53,493 INFO L895 garLoopResultBuilder]: At program point L721-1(lines 721 727) the Hoare annotation is: (let ((.cse1 (<= ~waterLevel~0 2)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and (<= ~waterLevel~0 1) .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2))) [2022-11-03 02:54:53,493 INFO L895 garLoopResultBuilder]: At program point L746(lines 701 748) the Hoare annotation is: (let ((.cse2 (<= ~waterLevel~0 1)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2) .cse1) (and (= ~pumpRunning~0 0) .cse2 .cse0 .cse1) (and .cse2 .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-03 02:54:53,493 INFO L895 garLoopResultBuilder]: At program point L713(line 713) the Hoare annotation is: (let ((.cse6 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0)) (.cse7 (<= ~waterLevel~0 1))) (let ((.cse2 (or (<= ~waterLevel~0 0) (and .cse0 .cse7))) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (or (and .cse6 .cse1 (<= ~waterLevel~0 2) .cse3) (and (not .cse0) .cse7 .cse1 (<= 1 ~waterLevel~0) .cse3)))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse5) (and .cse1 .cse2 .cse4 .cse3) (and .cse6 .cse5)))) [2022-11-03 02:54:53,493 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-03 02:54:53,493 INFO L895 garLoopResultBuilder]: At program point L739-2(lines 731 744) the Hoare annotation is: (let ((.cse1 (<= ~waterLevel~0 2)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and (<= ~waterLevel~0 1) .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2))) [2022-11-03 02:54:53,494 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-03 02:54:53,494 INFO L899 garLoopResultBuilder]: For program point L702(lines 701 748) no Hoare annotation was computed. [2022-11-03 02:54:53,494 INFO L895 garLoopResultBuilder]: At program point L723(line 723) the Hoare annotation is: (let ((.cse1 (<= ~waterLevel~0 2)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and (<= ~waterLevel~0 1) .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2))) [2022-11-03 02:54:53,494 INFO L902 garLoopResultBuilder]: At program point L752(lines 691 756) the Hoare annotation is: true [2022-11-03 02:54:53,494 INFO L899 garLoopResultBuilder]: For program point L711(lines 711 717) no Hoare annotation was computed. [2022-11-03 02:54:53,495 INFO L899 garLoopResultBuilder]: For program point L711-1(lines 711 717) no Hoare annotation was computed. [2022-11-03 02:54:53,495 INFO L895 garLoopResultBuilder]: At program point L749(lines 700 750) the Hoare annotation is: false [2022-11-03 02:54:53,495 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 798 822) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= 0 ~systemActive~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-03 02:54:53,495 INFO L895 garLoopResultBuilder]: At program point L812(line 812) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (= ~switchedOnBeforeTS~0 0) .cse2) (or .cse0 (and (or (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 1) .cse3) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1 .cse2) (or .cse3 (not (<= ~waterLevel~0 1)) .cse1 .cse2))) [2022-11-03 02:54:53,496 INFO L895 garLoopResultBuilder]: At program point L806(lines 806 814) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (= ~switchedOnBeforeTS~0 0) .cse2) (or .cse0 (and (or (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 1) .cse3) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1 .cse2) (or .cse3 (not (<= ~waterLevel~0 1)) .cse1 .cse2))) [2022-11-03 02:54:53,496 INFO L895 garLoopResultBuilder]: At program point L802(lines 802 819) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= 0 ~systemActive~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-03 02:54:53,496 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 798 822) no Hoare annotation was computed. [2022-11-03 02:54:53,496 INFO L895 garLoopResultBuilder]: At program point L817(line 817) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1 .cse2))) [2022-11-03 02:54:53,496 INFO L899 garLoopResultBuilder]: For program point L817-1(lines 798 822) no Hoare annotation was computed. [2022-11-03 02:54:53,496 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2022-11-03 02:54:53,497 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse2 .cse0 .cse1 (not (<= |old(~waterLevel~0)| 0))) (or .cse3 (not (= ~pumpRunning~0 0)) .cse0 .cse1) (or .cse3 (not (<= 1 |old(~waterLevel~0)|)) (and (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0)) .cse2 .cse1))) [2022-11-03 02:54:53,497 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 894 902) no Hoare annotation was computed. [2022-11-03 02:54:53,497 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 894 902) the Hoare annotation is: true [2022-11-03 02:54:53,501 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-03 02:54:53,503 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-03 02:54:53,536 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 03.11 02:54:53 BoogieIcfgContainer [2022-11-03 02:54:53,536 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-03 02:54:53,537 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-03 02:54:53,537 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-03 02:54:53,537 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-03 02:54:53,538 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 03.11 02:53:25" (3/4) ... [2022-11-03 02:54:53,542 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-03 02:54:53,548 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-03 02:54:53,548 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-03 02:54:53,548 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-03 02:54:53,548 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-03 02:54:53,549 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-03 02:54:53,549 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-03 02:54:53,549 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-03 02:54:53,558 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 82 nodes and edges [2022-11-03 02:54:53,559 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 29 nodes and edges [2022-11-03 02:54:53,559 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-03 02:54:53,560 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-03 02:54:53,560 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-03 02:54:53,561 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 02:54:53,562 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-03 02:54:53,591 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || \old(switchedOnBeforeTS) == 0) [2022-11-03 02:54:53,592 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) && ((((((((pumpRunning == \old(pumpRunning) && !(\old(pumpRunning) == 0)) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0)))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) [2022-11-03 02:54:53,592 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(waterLevel) == waterLevel + 1) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || \old(switchedOnBeforeTS) == 0) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && waterLevel == 1) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((((pumpRunning == \old(pumpRunning) && tmp == waterLevel) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || 0 == systemActive) || ((((pumpRunning == \old(pumpRunning) && tmp == waterLevel) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || \old(switchedOnBeforeTS) == 0) [2022-11-03 02:54:53,592 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == switchedOnBeforeTS) && ((pumpRunning == 0 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel))) [2022-11-03 02:54:53,593 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || 0 == systemActive)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-11-03 02:54:53,593 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) && ((((((((pumpRunning == \old(pumpRunning) && !(\old(pumpRunning) == 0)) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0)))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) [2022-11-03 02:54:53,593 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(waterLevel <= 2) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) [2022-11-03 02:54:53,594 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-03 02:54:53,595 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(waterLevel <= 2) || 0 == systemActive) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning))) && (((!(waterLevel <= 2) || ((tmp == 1 || tmp == 0) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning)))) && (((tmp == 0 || !(waterLevel <= 1)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-03 02:54:53,622 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/witness.graphml [2022-11-03 02:54:53,623 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-03 02:54:53,624 INFO L158 Benchmark]: Toolchain (without parser) took 89427.09ms. Allocated memory was 153.1MB in the beginning and 585.1MB in the end (delta: 432.0MB). Free memory was 118.6MB in the beginning and 504.6MB in the end (delta: -386.0MB). Peak memory consumption was 45.2MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,624 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 92.3MB. Free memory was 64.2MB in the beginning and 64.2MB in the end (delta: 29.1kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-03 02:54:53,624 INFO L158 Benchmark]: CACSL2BoogieTranslator took 550.59ms. Allocated memory is still 153.1MB. Free memory was 118.6MB in the beginning and 119.6MB in the end (delta: -957.8kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,625 INFO L158 Benchmark]: Boogie Procedure Inliner took 80.31ms. Allocated memory is still 153.1MB. Free memory was 119.6MB in the beginning and 117.0MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,625 INFO L158 Benchmark]: Boogie Preprocessor took 51.45ms. Allocated memory is still 153.1MB. Free memory was 116.8MB in the beginning and 115.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,626 INFO L158 Benchmark]: RCFGBuilder took 796.96ms. Allocated memory is still 153.1MB. Free memory was 115.1MB in the beginning and 80.3MB in the end (delta: 34.7MB). Peak memory consumption was 35.7MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,626 INFO L158 Benchmark]: TraceAbstraction took 87846.35ms. Allocated memory was 153.1MB in the beginning and 585.1MB in the end (delta: 432.0MB). Free memory was 79.9MB in the beginning and 509.9MB in the end (delta: -430.0MB). Peak memory consumption was 315.0MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,626 INFO L158 Benchmark]: Witness Printer took 86.15ms. Allocated memory is still 585.1MB. Free memory was 509.9MB in the beginning and 504.6MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-03 02:54:53,629 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 92.3MB. Free memory was 64.2MB in the beginning and 64.2MB in the end (delta: 29.1kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 550.59ms. Allocated memory is still 153.1MB. Free memory was 118.6MB in the beginning and 119.6MB in the end (delta: -957.8kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 80.31ms. Allocated memory is still 153.1MB. Free memory was 119.6MB in the beginning and 117.0MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 51.45ms. Allocated memory is still 153.1MB. Free memory was 116.8MB in the beginning and 115.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 796.96ms. Allocated memory is still 153.1MB. Free memory was 115.1MB in the beginning and 80.3MB in the end (delta: 34.7MB). Peak memory consumption was 35.7MB. Max. memory is 16.1GB. * TraceAbstraction took 87846.35ms. Allocated memory was 153.1MB in the beginning and 585.1MB in the end (delta: 432.0MB). Free memory was 79.9MB in the beginning and 509.9MB in the end (delta: -430.0MB). Peak memory consumption was 315.0MB. Max. memory is 16.1GB. * Witness Printer took 86.15ms. Allocated memory is still 585.1MB. Free memory was 509.9MB in the beginning and 504.6MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 685]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 58 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 87.7s, OverallIterations: 9, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 9.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 6.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2227 SdHoareTripleChecker+Valid, 4.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2199 mSDsluCounter, 2351 SdHoareTripleChecker+Invalid, 3.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2258 mSDsCounter, 1409 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4161 IncrementalHoareTripleChecker+Invalid, 5570 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1409 mSolverCounterUnsat, 588 mSDtfsCounter, 4161 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 873 GetRequests, 591 SyntacticMatches, 13 SemanticMatches, 269 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8057 ImplicationChecksByTransitivity, 35.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=438occurred in iteration=8, InterpolantAutomatonStates: 166, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 9 MinimizatonAttempts, 108 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 36 LocationsWithAnnotation, 1334 PreInvPairs, 1635 NumberOfFragments, 1816 HoareAnnotationTreeSize, 1334 FomulaSimplifications, 4894 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 36 FomulaSimplificationsInter, 20692 FormulaSimplificationTreeSizeReductionInter, 6.0s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 5.0s InterpolantComputationTime, 602 NumberOfCodeBlocks, 602 NumberOfCodeBlocksAsserted, 12 NumberOfCheckSat, 795 ConstructedInterpolants, 0 QuantifiedInterpolants, 2907 SizeOfPredicates, 27 NumberOfNonLiveVariables, 1486 ConjunctsInSsa, 65 ConjunctsInUnsatCore, 15 InterpolantComputations, 6 PerfectInterpolantSequences, 310/413 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 685]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || 0 == systemActive)) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 701]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive)) || (((pumpRunning == 0 && waterLevel <= 1) && splverifierCounter == 0) && !(0 == systemActive))) || (((waterLevel <= 1 && splverifierCounter == 0) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive)) - InvariantResult [Line: 806]: Loop Invariant Derived loop invariant: ((((!(waterLevel <= 2) || 0 == systemActive) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning))) && (((!(waterLevel <= 2) || ((tmp == 1 || tmp == 0) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning)))) && (((tmp == 0 || !(waterLevel <= 1)) || 0 == systemActive) || !(switchedOnBeforeTS == \old(pumpRunning))) - InvariantResult [Line: 700]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 691]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 721]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive)) || (((pumpRunning == 0 && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive))) || (((waterLevel <= 1 && splverifierCounter == 0) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive)) - InvariantResult [Line: 580]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 828]: Loop Invariant Derived loop invariant: ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == switchedOnBeforeTS) && ((pumpRunning == 0 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 667]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && waterLevel == 1) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive) - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: (((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(waterLevel) == waterLevel + 1) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) || \old(switchedOnBeforeTS) == 0) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && waterLevel == 1) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || ((((pumpRunning == \old(pumpRunning) && tmp == waterLevel) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) && (!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel))) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || 0 == systemActive) || ((((pumpRunning == \old(pumpRunning) && tmp == waterLevel) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 667]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) && ((((((((pumpRunning == \old(pumpRunning) && !(\old(pumpRunning) == 0)) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0)))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) - InvariantResult [Line: 590]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 177]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS)) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && aux-isPumpRunning()-aux == pumpRunning)) || 0 == systemActive)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 832]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 802]: Loop Invariant Derived loop invariant: ((!(waterLevel <= 2) || 0 == systemActive) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) - InvariantResult [Line: 777]: Loop Invariant Derived loop invariant: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) && ((((((((pumpRunning == \old(pumpRunning) && !(\old(pumpRunning) == 0)) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(pumpRunning == 0)))) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) || !(2 <= \old(waterLevel)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || 0 == systemActive) RESULT: Ultimate proved your program to be correct! [2022-11-03 02:54:53,702 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9dc013af-af9e-4adb-bde1-a495f72a553f/bin/utaipan-7li7fVZpFI/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE