./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 5ed8e4dea18b15d78522f05bcbacefb8bf743c0552ef5a7415602905a04fdc4c --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 15:52:38,608 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 15:52:38,610 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 15:52:38,635 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 15:52:38,636 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 15:52:38,637 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 15:52:38,638 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 15:52:38,640 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 15:52:38,642 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 15:52:38,644 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 15:52:38,645 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 15:52:38,646 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 15:52:38,647 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 15:52:38,648 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 15:52:38,649 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 15:52:38,651 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 15:52:38,652 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 15:52:38,653 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 15:52:38,655 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 15:52:38,657 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 15:52:38,659 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 15:52:38,661 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 15:52:38,662 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 15:52:38,663 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 15:52:38,667 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 15:52:38,668 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 15:52:38,668 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 15:52:38,669 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 15:52:38,670 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 15:52:38,671 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 15:52:38,672 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 15:52:38,673 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 15:52:38,674 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 15:52:38,675 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 15:52:38,676 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 15:52:38,676 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 15:52:38,677 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 15:52:38,677 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 15:52:38,678 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 15:52:38,679 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 15:52:38,680 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 15:52:38,681 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-16 15:52:38,705 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 15:52:38,705 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 15:52:38,705 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 15:52:38,706 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 15:52:38,706 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 15:52:38,707 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 15:52:38,707 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-16 15:52:38,707 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-16 15:52:38,708 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-16 15:52:38,708 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-16 15:52:38,708 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-16 15:52:38,708 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-16 15:52:38,709 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-16 15:52:38,709 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-16 15:52:38,709 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-16 15:52:38,709 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-16 15:52:38,710 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-16 15:52:38,710 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-16 15:52:38,711 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 15:52:38,711 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 15:52:38,711 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 15:52:38,711 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 15:52:38,712 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 15:52:38,712 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 15:52:38,712 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 15:52:38,712 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 15:52:38,713 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 15:52:38,713 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 15:52:38,713 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 15:52:38,713 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 15:52:38,714 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 15:52:38,714 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 15:52:38,714 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 15:52:38,714 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 15:52:38,715 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-16 15:52:38,715 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 15:52:38,715 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 15:52:38,715 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-16 15:52:38,716 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 15:52:38,716 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 15:52:38,716 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-16 15:52:38,716 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 5ed8e4dea18b15d78522f05bcbacefb8bf743c0552ef5a7415602905a04fdc4c [2022-11-16 15:52:38,975 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 15:52:39,002 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 15:52:39,005 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 15:52:39,007 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 15:52:39,008 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 15:52:39,010 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/../../sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c [2022-11-16 15:52:39,079 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/data/bcb12b5d3/74c1526db87f42e180dd750ddba67bca/FLAGd2de3adad [2022-11-16 15:52:39,579 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 15:52:39,580 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c [2022-11-16 15:52:39,599 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/data/bcb12b5d3/74c1526db87f42e180dd750ddba67bca/FLAGd2de3adad [2022-11-16 15:52:39,980 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/data/bcb12b5d3/74c1526db87f42e180dd750ddba67bca [2022-11-16 15:52:39,986 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 15:52:39,990 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 15:52:39,995 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 15:52:39,996 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 15:52:40,002 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 15:52:40,003 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 03:52:39" (1/1) ... [2022-11-16 15:52:40,008 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@62504638 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40, skipping insertion in model container [2022-11-16 15:52:40,009 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 03:52:39" (1/1) ... [2022-11-16 15:52:40,019 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 15:52:40,082 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 15:52:40,268 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c[1605,1618] [2022-11-16 15:52:40,404 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 15:52:40,426 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 15:52:40,441 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/sv-benchmarks/c/product-lines/minepump_spec1_product58.cil.c[1605,1618] [2022-11-16 15:52:40,518 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 15:52:40,538 INFO L208 MainTranslator]: Completed translation [2022-11-16 15:52:40,548 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40 WrapperNode [2022-11-16 15:52:40,548 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 15:52:40,555 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 15:52:40,555 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 15:52:40,555 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 15:52:40,566 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,582 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,614 INFO L138 Inliner]: procedures = 57, calls = 157, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 271 [2022-11-16 15:52:40,614 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 15:52:40,615 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 15:52:40,616 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 15:52:40,616 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 15:52:40,626 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,627 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,630 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,630 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,636 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,641 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,643 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,644 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,647 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 15:52:40,648 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 15:52:40,649 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 15:52:40,649 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 15:52:40,650 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (1/1) ... [2022-11-16 15:52:40,658 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 15:52:40,672 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 15:52:40,709 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 15:52:40,712 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 15:52:40,756 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 15:52:40,757 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 15:52:40,757 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 15:52:40,757 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 15:52:40,757 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 15:52:40,757 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 15:52:40,757 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 15:52:40,758 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-16 15:52:40,758 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-16 15:52:40,758 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 15:52:40,758 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 15:52:40,758 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 15:52:40,758 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 15:52:40,758 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 15:52:40,759 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 15:52:40,759 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 15:52:40,759 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 15:52:40,759 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 15:52:40,843 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 15:52:40,847 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 15:52:41,267 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 15:52:41,444 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 15:52:41,445 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 15:52:41,448 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 03:52:41 BoogieIcfgContainer [2022-11-16 15:52:41,448 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 15:52:41,451 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 15:52:41,451 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 15:52:41,456 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 15:52:41,456 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 03:52:39" (1/3) ... [2022-11-16 15:52:41,457 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@17ce5f6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 03:52:41, skipping insertion in model container [2022-11-16 15:52:41,458 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 03:52:40" (2/3) ... [2022-11-16 15:52:41,458 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@17ce5f6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 03:52:41, skipping insertion in model container [2022-11-16 15:52:41,459 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 03:52:41" (3/3) ... [2022-11-16 15:52:41,460 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product58.cil.c [2022-11-16 15:52:41,482 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 15:52:41,482 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 15:52:41,553 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 15:52:41,564 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4a40031b, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 15:52:41,567 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 15:52:41,571 INFO L276 IsEmpty]: Start isEmpty. Operand has 57 states, 36 states have (on average 1.4166666666666667) internal successors, (51), 44 states have internal predecessors, (51), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-16 15:52:41,584 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 17 [2022-11-16 15:52:41,584 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:41,585 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:41,586 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:41,598 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:41,598 INFO L85 PathProgramCache]: Analyzing trace with hash -239157303, now seen corresponding path program 1 times [2022-11-16 15:52:41,621 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:41,622 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1362268342] [2022-11-16 15:52:41,622 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:41,623 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:41,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:41,908 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 15:52:41,909 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:41,910 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1362268342] [2022-11-16 15:52:41,910 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1362268342] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:52:41,911 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:52:41,911 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 15:52:41,913 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1066845033] [2022-11-16 15:52:41,914 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:52:41,919 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 15:52:41,920 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:52:41,952 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 15:52:41,953 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 15:52:41,955 INFO L87 Difference]: Start difference. First operand has 57 states, 36 states have (on average 1.4166666666666667) internal successors, (51), 44 states have internal predecessors, (51), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:42,076 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:52:42,076 INFO L93 Difference]: Finished difference Result 112 states and 151 transitions. [2022-11-16 15:52:42,077 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 15:52:42,079 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 16 [2022-11-16 15:52:42,079 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:52:42,089 INFO L225 Difference]: With dead ends: 112 [2022-11-16 15:52:42,090 INFO L226 Difference]: Without dead ends: 52 [2022-11-16 15:52:42,100 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 15:52:42,105 INFO L413 NwaCegarLoop]: 55 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 55 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 15:52:42,108 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 55 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 15:52:42,128 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 52 states. [2022-11-16 15:52:42,172 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 52 to 52. [2022-11-16 15:52:42,174 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 52 states, 33 states have (on average 1.303030303030303) internal successors, (43), 40 states have internal predecessors, (43), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 15:52:42,181 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 52 states to 52 states and 66 transitions. [2022-11-16 15:52:42,183 INFO L78 Accepts]: Start accepts. Automaton has 52 states and 66 transitions. Word has length 16 [2022-11-16 15:52:42,184 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:52:42,184 INFO L495 AbstractCegarLoop]: Abstraction has 52 states and 66 transitions. [2022-11-16 15:52:42,185 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 6.0) internal successors, (12), 2 states have internal predecessors, (12), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:42,186 INFO L276 IsEmpty]: Start isEmpty. Operand 52 states and 66 transitions. [2022-11-16 15:52:42,193 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 18 [2022-11-16 15:52:42,193 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:42,194 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:42,195 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 15:52:42,195 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:42,197 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:42,197 INFO L85 PathProgramCache]: Analyzing trace with hash 1782890685, now seen corresponding path program 1 times [2022-11-16 15:52:42,198 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:42,198 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [871689790] [2022-11-16 15:52:42,199 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:42,199 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:42,248 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:42,349 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 15:52:42,350 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:42,350 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [871689790] [2022-11-16 15:52:42,350 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [871689790] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:52:42,350 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:52:42,351 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 15:52:42,351 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1016569555] [2022-11-16 15:52:42,351 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:52:42,352 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 15:52:42,353 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:52:42,353 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 15:52:42,354 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 15:52:42,354 INFO L87 Difference]: Start difference. First operand 52 states and 66 transitions. Second operand has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:42,402 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:52:42,402 INFO L93 Difference]: Finished difference Result 81 states and 103 transitions. [2022-11-16 15:52:42,403 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 15:52:42,403 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 17 [2022-11-16 15:52:42,403 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:52:42,404 INFO L225 Difference]: With dead ends: 81 [2022-11-16 15:52:42,404 INFO L226 Difference]: Without dead ends: 44 [2022-11-16 15:52:42,405 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 15:52:42,406 INFO L413 NwaCegarLoop]: 41 mSDtfsCounter, 7 mSDsluCounter, 32 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 73 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 15:52:42,407 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 73 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 15:52:42,408 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 44 states. [2022-11-16 15:52:42,415 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 44 to 44. [2022-11-16 15:52:42,418 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 44 states, 28 states have (on average 1.3214285714285714) internal successors, (37), 35 states have internal predecessors, (37), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-16 15:52:42,419 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 44 states to 44 states and 55 transitions. [2022-11-16 15:52:42,420 INFO L78 Accepts]: Start accepts. Automaton has 44 states and 55 transitions. Word has length 17 [2022-11-16 15:52:42,421 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:52:42,421 INFO L495 AbstractCegarLoop]: Abstraction has 44 states and 55 transitions. [2022-11-16 15:52:42,422 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.333333333333333) internal successors, (13), 3 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:42,422 INFO L276 IsEmpty]: Start isEmpty. Operand 44 states and 55 transitions. [2022-11-16 15:52:42,423 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-11-16 15:52:42,424 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:42,424 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:42,425 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 15:52:42,425 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:42,425 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:42,426 INFO L85 PathProgramCache]: Analyzing trace with hash -1551440202, now seen corresponding path program 1 times [2022-11-16 15:52:42,427 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:42,427 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1095390314] [2022-11-16 15:52:42,428 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:42,428 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:42,464 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:42,717 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 15:52:42,717 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:42,717 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1095390314] [2022-11-16 15:52:42,717 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1095390314] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:52:42,718 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:52:42,718 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 15:52:42,719 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1577259984] [2022-11-16 15:52:42,720 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:52:42,720 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 15:52:42,720 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:52:42,726 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 15:52:42,726 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-16 15:52:42,727 INFO L87 Difference]: Start difference. First operand 44 states and 55 transitions. Second operand has 6 states, 5 states have (on average 3.2) internal successors, (16), 4 states have internal predecessors, (16), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:42,977 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:52:42,978 INFO L93 Difference]: Finished difference Result 126 states and 161 transitions. [2022-11-16 15:52:42,978 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-16 15:52:42,979 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 3.2) internal successors, (16), 4 states have internal predecessors, (16), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 19 [2022-11-16 15:52:42,979 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:52:42,980 INFO L225 Difference]: With dead ends: 126 [2022-11-16 15:52:42,981 INFO L226 Difference]: Without dead ends: 84 [2022-11-16 15:52:42,982 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-16 15:52:42,983 INFO L413 NwaCegarLoop]: 48 mSDtfsCounter, 37 mSDsluCounter, 161 mSDsCounter, 0 mSdLazyCounter, 98 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 40 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 99 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 98 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 15:52:42,984 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [40 Valid, 209 Invalid, 99 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 98 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 15:52:42,985 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 84 states. [2022-11-16 15:52:42,996 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 84 to 80. [2022-11-16 15:52:42,997 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 51 states have (on average 1.3137254901960784) internal successors, (67), 63 states have internal predecessors, (67), 17 states have call successors, (17), 11 states have call predecessors, (17), 11 states have return successors, (17), 13 states have call predecessors, (17), 17 states have call successors, (17) [2022-11-16 15:52:42,998 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 101 transitions. [2022-11-16 15:52:42,999 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 101 transitions. Word has length 19 [2022-11-16 15:52:42,999 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:52:42,999 INFO L495 AbstractCegarLoop]: Abstraction has 80 states and 101 transitions. [2022-11-16 15:52:43,000 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 3.2) internal successors, (16), 4 states have internal predecessors, (16), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 15:52:43,000 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 101 transitions. [2022-11-16 15:52:43,003 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-16 15:52:43,003 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:43,004 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:43,004 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 15:52:43,004 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:43,005 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:43,005 INFO L85 PathProgramCache]: Analyzing trace with hash -1880661992, now seen corresponding path program 1 times [2022-11-16 15:52:43,005 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:43,006 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1868615742] [2022-11-16 15:52:43,006 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:43,006 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:43,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:43,123 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 15:52:43,124 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:43,124 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1868615742] [2022-11-16 15:52:43,124 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1868615742] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:52:43,124 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:52:43,124 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-16 15:52:43,125 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [283272258] [2022-11-16 15:52:43,125 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:52:43,125 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-16 15:52:43,126 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:52:43,126 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-16 15:52:43,126 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-16 15:52:43,127 INFO L87 Difference]: Start difference. First operand 80 states and 101 transitions. Second operand has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 15:52:43,216 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:52:43,216 INFO L93 Difference]: Finished difference Result 222 states and 288 transitions. [2022-11-16 15:52:43,217 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-16 15:52:43,217 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-16 15:52:43,217 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:52:43,223 INFO L225 Difference]: With dead ends: 222 [2022-11-16 15:52:43,223 INFO L226 Difference]: Without dead ends: 144 [2022-11-16 15:52:43,228 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-16 15:52:43,230 INFO L413 NwaCegarLoop]: 48 mSDtfsCounter, 34 mSDsluCounter, 81 mSDsCounter, 0 mSdLazyCounter, 46 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 34 SdHoareTripleChecker+Valid, 129 SdHoareTripleChecker+Invalid, 52 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 46 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 15:52:43,231 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [34 Valid, 129 Invalid, 52 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 46 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 15:52:43,232 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 144 states. [2022-11-16 15:52:43,250 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 144 to 140. [2022-11-16 15:52:43,250 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 140 states, 93 states have (on average 1.2473118279569892) internal successors, (116), 104 states have internal predecessors, (116), 24 states have call successors, (24), 22 states have call predecessors, (24), 22 states have return successors, (32), 24 states have call predecessors, (32), 24 states have call successors, (32) [2022-11-16 15:52:43,252 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 140 states to 140 states and 172 transitions. [2022-11-16 15:52:43,252 INFO L78 Accepts]: Start accepts. Automaton has 140 states and 172 transitions. Word has length 22 [2022-11-16 15:52:43,252 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:52:43,253 INFO L495 AbstractCegarLoop]: Abstraction has 140 states and 172 transitions. [2022-11-16 15:52:43,253 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.25) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-16 15:52:43,253 INFO L276 IsEmpty]: Start isEmpty. Operand 140 states and 172 transitions. [2022-11-16 15:52:43,254 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2022-11-16 15:52:43,254 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:43,255 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:43,255 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 15:52:43,255 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:43,256 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:43,256 INFO L85 PathProgramCache]: Analyzing trace with hash -381716183, now seen corresponding path program 1 times [2022-11-16 15:52:43,256 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:43,256 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [642657529] [2022-11-16 15:52:43,256 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:43,257 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:43,277 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:43,669 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 15:52:43,669 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:43,669 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [642657529] [2022-11-16 15:52:43,669 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [642657529] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:52:43,670 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:52:43,670 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-16 15:52:43,670 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [508204280] [2022-11-16 15:52:43,670 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:52:43,671 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 15:52:43,671 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:52:43,671 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 15:52:43,672 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-16 15:52:43,672 INFO L87 Difference]: Start difference. First operand 140 states and 172 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-16 15:52:43,947 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:52:43,947 INFO L93 Difference]: Finished difference Result 396 states and 484 transitions. [2022-11-16 15:52:43,948 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-16 15:52:43,948 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 34 [2022-11-16 15:52:43,949 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:52:43,951 INFO L225 Difference]: With dead ends: 396 [2022-11-16 15:52:43,951 INFO L226 Difference]: Without dead ends: 258 [2022-11-16 15:52:43,952 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-16 15:52:43,953 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 70 mSDsluCounter, 152 mSDsCounter, 0 mSdLazyCounter, 164 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 71 SdHoareTripleChecker+Valid, 220 SdHoareTripleChecker+Invalid, 174 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 164 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-16 15:52:43,954 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [71 Valid, 220 Invalid, 174 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 164 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-16 15:52:43,955 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 258 states. [2022-11-16 15:52:44,012 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 258 to 227. [2022-11-16 15:52:44,013 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 227 states, 152 states have (on average 1.2105263157894737) internal successors, (184), 164 states have internal predecessors, (184), 35 states have call successors, (35), 35 states have call predecessors, (35), 39 states have return successors, (47), 37 states have call predecessors, (47), 35 states have call successors, (47) [2022-11-16 15:52:44,024 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 227 states to 227 states and 266 transitions. [2022-11-16 15:52:44,025 INFO L78 Accepts]: Start accepts. Automaton has 227 states and 266 transitions. Word has length 34 [2022-11-16 15:52:44,025 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:52:44,025 INFO L495 AbstractCegarLoop]: Abstraction has 227 states and 266 transitions. [2022-11-16 15:52:44,025 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-16 15:52:44,026 INFO L276 IsEmpty]: Start isEmpty. Operand 227 states and 266 transitions. [2022-11-16 15:52:44,027 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2022-11-16 15:52:44,027 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:52:44,028 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:52:44,028 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 15:52:44,028 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:52:44,028 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:52:44,029 INFO L85 PathProgramCache]: Analyzing trace with hash 1342412146, now seen corresponding path program 1 times [2022-11-16 15:52:44,029 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:52:44,029 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1547735977] [2022-11-16 15:52:44,029 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:44,029 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:52:44,062 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:44,432 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 15:52:44,433 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:52:44,433 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1547735977] [2022-11-16 15:52:44,433 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1547735977] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 15:52:44,433 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1687678469] [2022-11-16 15:52:44,433 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:52:44,434 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:52:44,434 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 15:52:44,439 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 15:52:44,459 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 15:52:44,567 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:52:44,571 INFO L263 TraceCheckSpWp]: Trace formula consists of 351 conjuncts, 31 conjunts are in the unsatisfiable core [2022-11-16 15:52:44,578 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 15:52:44,956 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 15:52:44,957 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 15:52:45,396 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 15:52:45,397 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1687678469] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 15:52:45,397 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [145310529] [2022-11-16 15:52:45,422 INFO L159 IcfgInterpreter]: Started Sifa with 36 locations of interest [2022-11-16 15:52:45,422 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 15:52:45,426 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 15:52:45,432 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 15:52:45,433 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 15:52:51,442 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 294 for LOIs [2022-11-16 15:52:51,523 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 314 for LOIs [2022-11-16 15:52:53,686 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 311 for LOIs [2022-11-16 15:52:56,075 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 43 for LOIs [2022-11-16 15:52:56,082 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 292 for LOIs [2022-11-16 15:52:56,145 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 15:53:40,347 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '2673#(and (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 0)) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~6#1|) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 0)) (<= ~methaneLevelCritical~0 1) (<= ~pumpRunning~0 1) (= ~head~0.offset 0) (<= 2 ~waterLevel~0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (<= 2 |old(~waterLevel~0)|) (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| ~methaneLevelCritical~0) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~6#1|) (<= 0 ~methaneLevelCritical~0) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1|) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-16 15:53:40,348 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 15:53:40,348 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 15:53:40,348 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 10, 10] total 24 [2022-11-16 15:53:40,348 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1600705914] [2022-11-16 15:53:40,349 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 15:53:40,350 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 24 states [2022-11-16 15:53:40,351 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:53:40,351 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 24 interpolants. [2022-11-16 15:53:40,353 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=328, Invalid=2122, Unknown=0, NotChecked=0, Total=2450 [2022-11-16 15:53:40,356 INFO L87 Difference]: Start difference. First operand 227 states and 266 transitions. Second operand has 24 states, 18 states have (on average 3.1666666666666665) internal successors, (57), 18 states have internal predecessors, (57), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) [2022-11-16 15:53:45,812 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:53:45,812 INFO L93 Difference]: Finished difference Result 956 states and 1247 transitions. [2022-11-16 15:53:45,813 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 72 states. [2022-11-16 15:53:45,814 INFO L78 Accepts]: Start accepts. Automaton has has 24 states, 18 states have (on average 3.1666666666666665) internal successors, (57), 18 states have internal predecessors, (57), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) Word has length 37 [2022-11-16 15:53:45,814 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:53:45,821 INFO L225 Difference]: With dead ends: 956 [2022-11-16 15:53:45,821 INFO L226 Difference]: Without dead ends: 717 [2022-11-16 15:53:45,827 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 201 GetRequests, 85 SyntacticMatches, 3 SemanticMatches, 113 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4837 ImplicationChecksByTransitivity, 47.6s TimeCoverageRelationStatistics Valid=1541, Invalid=11569, Unknown=0, NotChecked=0, Total=13110 [2022-11-16 15:53:45,828 INFO L413 NwaCegarLoop]: 44 mSDtfsCounter, 949 mSDsluCounter, 300 mSDsCounter, 0 mSdLazyCounter, 2428 mSolverCounterSat, 802 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 954 SdHoareTripleChecker+Valid, 344 SdHoareTripleChecker+Invalid, 3230 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 802 IncrementalHoareTripleChecker+Valid, 2428 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.2s IncrementalHoareTripleChecker+Time [2022-11-16 15:53:45,828 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [954 Valid, 344 Invalid, 3230 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [802 Valid, 2428 Invalid, 0 Unknown, 0 Unchecked, 2.2s Time] [2022-11-16 15:53:45,830 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 717 states. [2022-11-16 15:53:45,905 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 717 to 526. [2022-11-16 15:53:45,906 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 526 states, 354 states have (on average 1.1751412429378532) internal successors, (416), 380 states have internal predecessors, (416), 82 states have call successors, (82), 75 states have call predecessors, (82), 89 states have return successors, (110), 88 states have call predecessors, (110), 82 states have call successors, (110) [2022-11-16 15:53:45,910 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 526 states to 526 states and 608 transitions. [2022-11-16 15:53:45,911 INFO L78 Accepts]: Start accepts. Automaton has 526 states and 608 transitions. Word has length 37 [2022-11-16 15:53:45,911 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:53:45,911 INFO L495 AbstractCegarLoop]: Abstraction has 526 states and 608 transitions. [2022-11-16 15:53:45,912 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 24 states, 18 states have (on average 3.1666666666666665) internal successors, (57), 18 states have internal predecessors, (57), 7 states have call successors, (14), 6 states have call predecessors, (14), 10 states have return successors, (13), 11 states have call predecessors, (13), 7 states have call successors, (13) [2022-11-16 15:53:45,912 INFO L276 IsEmpty]: Start isEmpty. Operand 526 states and 608 transitions. [2022-11-16 15:53:45,914 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2022-11-16 15:53:45,914 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:53:45,914 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:53:45,926 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-16 15:53:46,121 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:53:46,121 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:53:46,122 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:53:46,122 INFO L85 PathProgramCache]: Analyzing trace with hash -235210955, now seen corresponding path program 1 times [2022-11-16 15:53:46,122 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:53:46,122 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1509340562] [2022-11-16 15:53:46,122 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:53:46,123 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:53:46,142 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:53:46,290 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-16 15:53:46,290 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:53:46,290 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1509340562] [2022-11-16 15:53:46,290 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1509340562] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 15:53:46,291 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 15:53:46,291 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-16 15:53:46,291 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [650975553] [2022-11-16 15:53:46,291 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 15:53:46,293 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-16 15:53:46,293 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:53:46,293 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-16 15:53:46,293 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-16 15:53:46,294 INFO L87 Difference]: Start difference. First operand 526 states and 608 transitions. Second operand has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-16 15:53:46,428 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:53:46,429 INFO L93 Difference]: Finished difference Result 1037 states and 1212 transitions. [2022-11-16 15:53:46,431 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-16 15:53:46,431 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 54 [2022-11-16 15:53:46,432 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:53:46,435 INFO L225 Difference]: With dead ends: 1037 [2022-11-16 15:53:46,435 INFO L226 Difference]: Without dead ends: 513 [2022-11-16 15:53:46,437 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-16 15:53:46,438 INFO L413 NwaCegarLoop]: 36 mSDtfsCounter, 37 mSDsluCounter, 35 mSDsCounter, 0 mSdLazyCounter, 33 mSolverCounterSat, 5 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 37 SdHoareTripleChecker+Valid, 71 SdHoareTripleChecker+Invalid, 38 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 5 IncrementalHoareTripleChecker+Valid, 33 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 15:53:46,438 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [37 Valid, 71 Invalid, 38 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [5 Valid, 33 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 15:53:46,439 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 513 states. [2022-11-16 15:53:46,513 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 513 to 481. [2022-11-16 15:53:46,514 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 481 states, 322 states have (on average 1.1428571428571428) internal successors, (368), 347 states have internal predecessors, (368), 76 states have call successors, (76), 71 states have call predecessors, (76), 82 states have return successors, (96), 80 states have call predecessors, (96), 76 states have call successors, (96) [2022-11-16 15:53:46,517 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 481 states to 481 states and 540 transitions. [2022-11-16 15:53:46,517 INFO L78 Accepts]: Start accepts. Automaton has 481 states and 540 transitions. Word has length 54 [2022-11-16 15:53:46,518 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:53:46,518 INFO L495 AbstractCegarLoop]: Abstraction has 481 states and 540 transitions. [2022-11-16 15:53:46,518 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-16 15:53:46,518 INFO L276 IsEmpty]: Start isEmpty. Operand 481 states and 540 transitions. [2022-11-16 15:53:46,520 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-16 15:53:46,520 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:53:46,521 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:53:46,521 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-16 15:53:46,521 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:53:46,522 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:53:46,522 INFO L85 PathProgramCache]: Analyzing trace with hash 1208317175, now seen corresponding path program 1 times [2022-11-16 15:53:46,522 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:53:46,522 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [362584041] [2022-11-16 15:53:46,522 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:53:46,523 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:53:46,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:53:47,242 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 5 proven. 10 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-16 15:53:47,242 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:53:47,242 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [362584041] [2022-11-16 15:53:47,243 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [362584041] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 15:53:47,243 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1692302651] [2022-11-16 15:53:47,243 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:53:47,243 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:53:47,243 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 15:53:47,244 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 15:53:47,283 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 15:53:47,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:53:47,385 INFO L263 TraceCheckSpWp]: Trace formula consists of 434 conjuncts, 38 conjunts are in the unsatisfiable core [2022-11-16 15:53:47,389 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 15:53:47,695 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 13 proven. 10 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 15:53:47,696 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 15:53:48,188 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 8 proven. 3 refuted. 0 times theorem prover too weak. 14 trivial. 0 not checked. [2022-11-16 15:53:48,188 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1692302651] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 15:53:48,188 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [554063186] [2022-11-16 15:53:48,191 INFO L159 IcfgInterpreter]: Started Sifa with 43 locations of interest [2022-11-16 15:53:48,191 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 15:53:48,192 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 15:53:48,192 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 15:53:48,192 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 15:53:54,063 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 23 for LOIs [2022-11-16 15:53:54,068 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-16 15:53:54,421 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 21 for LOIs [2022-11-16 15:53:54,541 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 48 for LOIs [2022-11-16 15:53:54,549 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 22 for LOIs [2022-11-16 15:53:54,551 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 24 for LOIs [2022-11-16 15:53:54,553 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 15:54:00,583 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '7893#(and (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 0)) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~6#1|) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 0)) (= ~head~0.offset 0) (= 1 ~systemActive~0) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 1) (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| ~methaneLevelCritical~0) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 2147483647) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~6#1|) (<= 0 (+ |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 2147483648)) (<= 0 ~methaneLevelCritical~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1|) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-16 15:54:00,584 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 15:54:00,584 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 15:54:00,584 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 12, 12] total 28 [2022-11-16 15:54:00,584 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [42614661] [2022-11-16 15:54:00,584 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 15:54:00,585 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 28 states [2022-11-16 15:54:00,585 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:54:00,587 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 28 interpolants. [2022-11-16 15:54:00,588 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=342, Invalid=2738, Unknown=0, NotChecked=0, Total=3080 [2022-11-16 15:54:00,588 INFO L87 Difference]: Start difference. First operand 481 states and 540 transitions. Second operand has 28 states, 25 states have (on average 3.52) internal successors, (88), 24 states have internal predecessors, (88), 11 states have call successors, (23), 9 states have call predecessors, (23), 9 states have return successors, (21), 8 states have call predecessors, (21), 11 states have call successors, (21) [2022-11-16 15:54:02,628 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:54:02,629 INFO L93 Difference]: Finished difference Result 1614 states and 1886 transitions. [2022-11-16 15:54:02,629 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 35 states. [2022-11-16 15:54:02,630 INFO L78 Accepts]: Start accepts. Automaton has has 28 states, 25 states have (on average 3.52) internal successors, (88), 24 states have internal predecessors, (88), 11 states have call successors, (23), 9 states have call predecessors, (23), 9 states have return successors, (21), 8 states have call predecessors, (21), 11 states have call successors, (21) Word has length 65 [2022-11-16 15:54:02,630 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:54:02,640 INFO L225 Difference]: With dead ends: 1614 [2022-11-16 15:54:02,640 INFO L226 Difference]: Without dead ends: 1264 [2022-11-16 15:54:02,644 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 237 GetRequests, 147 SyntacticMatches, 13 SemanticMatches, 77 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2893 ImplicationChecksByTransitivity, 7.2s TimeCoverageRelationStatistics Valid=818, Invalid=5344, Unknown=0, NotChecked=0, Total=6162 [2022-11-16 15:54:02,645 INFO L413 NwaCegarLoop]: 49 mSDtfsCounter, 765 mSDsluCounter, 415 mSDsCounter, 0 mSdLazyCounter, 1075 mSolverCounterSat, 495 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 770 SdHoareTripleChecker+Valid, 464 SdHoareTripleChecker+Invalid, 1570 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 495 IncrementalHoareTripleChecker+Valid, 1075 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-11-16 15:54:02,645 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [770 Valid, 464 Invalid, 1570 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [495 Valid, 1075 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-11-16 15:54:02,647 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1264 states. [2022-11-16 15:54:02,818 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1264 to 1095. [2022-11-16 15:54:02,820 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1095 states, 738 states have (on average 1.1422764227642277) internal successors, (843), 794 states have internal predecessors, (843), 174 states have call successors, (174), 148 states have call predecessors, (174), 182 states have return successors, (242), 190 states have call predecessors, (242), 174 states have call successors, (242) [2022-11-16 15:54:02,828 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1095 states to 1095 states and 1259 transitions. [2022-11-16 15:54:02,829 INFO L78 Accepts]: Start accepts. Automaton has 1095 states and 1259 transitions. Word has length 65 [2022-11-16 15:54:02,829 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:54:02,829 INFO L495 AbstractCegarLoop]: Abstraction has 1095 states and 1259 transitions. [2022-11-16 15:54:02,830 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 28 states, 25 states have (on average 3.52) internal successors, (88), 24 states have internal predecessors, (88), 11 states have call successors, (23), 9 states have call predecessors, (23), 9 states have return successors, (21), 8 states have call predecessors, (21), 11 states have call successors, (21) [2022-11-16 15:54:02,830 INFO L276 IsEmpty]: Start isEmpty. Operand 1095 states and 1259 transitions. [2022-11-16 15:54:02,837 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 115 [2022-11-16 15:54:02,837 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 15:54:02,837 INFO L195 NwaCegarLoop]: trace histogram [6, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:54:02,854 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 15:54:03,047 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:54:03,047 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 15:54:03,048 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 15:54:03,048 INFO L85 PathProgramCache]: Analyzing trace with hash -1718429194, now seen corresponding path program 1 times [2022-11-16 15:54:03,048 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 15:54:03,048 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [757297080] [2022-11-16 15:54:03,048 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:54:03,048 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 15:54:03,089 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:54:04,427 INFO L134 CoverageAnalysis]: Checked inductivity of 143 backedges. 51 proven. 53 refuted. 0 times theorem prover too weak. 39 trivial. 0 not checked. [2022-11-16 15:54:04,427 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 15:54:04,427 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [757297080] [2022-11-16 15:54:04,428 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [757297080] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 15:54:04,428 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [489589227] [2022-11-16 15:54:04,428 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 15:54:04,428 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:54:04,429 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 15:54:04,430 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 15:54:04,455 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 15:54:04,600 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 15:54:04,604 INFO L263 TraceCheckSpWp]: Trace formula consists of 600 conjuncts, 43 conjunts are in the unsatisfiable core [2022-11-16 15:54:04,611 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 15:54:05,352 INFO L134 CoverageAnalysis]: Checked inductivity of 143 backedges. 81 proven. 42 refuted. 0 times theorem prover too weak. 20 trivial. 0 not checked. [2022-11-16 15:54:05,353 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 15:54:06,377 INFO L134 CoverageAnalysis]: Checked inductivity of 143 backedges. 72 proven. 25 refuted. 0 times theorem prover too weak. 46 trivial. 0 not checked. [2022-11-16 15:54:06,377 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [489589227] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 15:54:06,378 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [101145082] [2022-11-16 15:54:06,381 INFO L159 IcfgInterpreter]: Started Sifa with 43 locations of interest [2022-11-16 15:54:06,381 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 15:54:06,382 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 15:54:06,382 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 15:54:06,382 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 15:54:12,396 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 23 for LOIs [2022-11-16 15:54:12,400 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-16 15:54:12,750 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 21 for LOIs [2022-11-16 15:54:12,874 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 48 for LOIs [2022-11-16 15:54:12,883 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 22 for LOIs [2022-11-16 15:54:12,885 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 24 for LOIs [2022-11-16 15:54:12,887 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 15:54:19,625 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '12878#(and (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 0)) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~6#1|) (not (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 0)) (= ~head~0.offset 0) (= 1 ~systemActive~0) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 1) (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| ~methaneLevelCritical~0) (<= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 2147483647) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~6#1|) (<= 0 (+ |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 2147483648)) (<= 0 ~methaneLevelCritical~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1|) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-16 15:54:19,625 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 15:54:19,625 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 15:54:19,626 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [18, 14, 14] total 37 [2022-11-16 15:54:19,626 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [721416786] [2022-11-16 15:54:19,626 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 15:54:19,626 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 37 states [2022-11-16 15:54:19,627 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 15:54:19,627 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 37 interpolants. [2022-11-16 15:54:19,628 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=441, Invalid=3719, Unknown=0, NotChecked=0, Total=4160 [2022-11-16 15:54:19,628 INFO L87 Difference]: Start difference. First operand 1095 states and 1259 transitions. Second operand has 37 states, 35 states have (on average 4.571428571428571) internal successors, (160), 36 states have internal predecessors, (160), 22 states have call successors, (36), 8 states have call predecessors, (36), 14 states have return successors, (38), 18 states have call predecessors, (38), 22 states have call successors, (38) [2022-11-16 15:54:20,800 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 15:54:20,800 INFO L93 Difference]: Finished difference Result 1467 states and 1695 transitions. [2022-11-16 15:54:20,801 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 19 states. [2022-11-16 15:54:20,801 INFO L78 Accepts]: Start accepts. Automaton has has 37 states, 35 states have (on average 4.571428571428571) internal successors, (160), 36 states have internal predecessors, (160), 22 states have call successors, (36), 8 states have call predecessors, (36), 14 states have return successors, (38), 18 states have call predecessors, (38), 22 states have call successors, (38) Word has length 114 [2022-11-16 15:54:20,802 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 15:54:20,802 INFO L225 Difference]: With dead ends: 1467 [2022-11-16 15:54:20,802 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 15:54:20,807 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 380 GetRequests, 287 SyntacticMatches, 16 SemanticMatches, 77 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2940 ImplicationChecksByTransitivity, 8.1s TimeCoverageRelationStatistics Valid=761, Invalid=5401, Unknown=0, NotChecked=0, Total=6162 [2022-11-16 15:54:20,807 INFO L413 NwaCegarLoop]: 40 mSDtfsCounter, 518 mSDsluCounter, 258 mSDsCounter, 0 mSdLazyCounter, 525 mSolverCounterSat, 333 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 521 SdHoareTripleChecker+Valid, 298 SdHoareTripleChecker+Invalid, 858 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 333 IncrementalHoareTripleChecker+Valid, 525 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-16 15:54:20,808 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [521 Valid, 298 Invalid, 858 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [333 Valid, 525 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-16 15:54:20,808 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 15:54:20,809 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 15:54:20,809 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 15:54:20,809 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 15:54:20,809 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 114 [2022-11-16 15:54:20,809 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 15:54:20,810 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 15:54:20,810 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 37 states, 35 states have (on average 4.571428571428571) internal successors, (160), 36 states have internal predecessors, (160), 22 states have call successors, (36), 8 states have call predecessors, (36), 14 states have return successors, (38), 18 states have call predecessors, (38), 22 states have call successors, (38) [2022-11-16 15:54:20,810 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 15:54:20,810 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 15:54:20,813 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 15:54:20,825 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 15:54:21,019 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 15:54:21,021 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 15:54:25,665 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 304 310) no Hoare annotation was computed. [2022-11-16 15:54:25,665 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 304 310) the Hoare annotation is: true [2022-11-16 15:54:25,666 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 93 104) the Hoare annotation is: (let ((.cse0 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 ~waterLevel~0)) .cse0 (not (<= ~waterLevel~0 1)) .cse1) (or .cse0 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse1))) [2022-11-16 15:54:25,666 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 93 104) no Hoare annotation was computed. [2022-11-16 15:54:25,666 INFO L895 garLoopResultBuilder]: At program point L506(line 506) the Hoare annotation is: (let ((.cse9 (= ~methaneLevelCritical~0 0))) (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (not .cse9))) (let ((.cse1 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (and .cse7 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 1))) (or (and .cse0 .cse8) (and .cse9 (= ~pumpRunning~0 1))))) (.cse3 (< |old(~waterLevel~0)| 2)) (.cse4 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and .cse0 .cse1 (= |timeShift_processEnvironment_~tmp~2#1| 1)) .cse2 .cse3 .cse4 .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse6 (and .cse0 .cse7) (not (<= 1 |old(~waterLevel~0)|)) .cse4) (or .cse1 .cse3 .cse8 (not (= |old(~pumpRunning~0)| 1)) .cse4 .cse5) (or .cse6 .cse2 .cse3 .cse4 .cse5))))) [2022-11-16 15:54:25,666 INFO L899 garLoopResultBuilder]: For program point L506-1(line 506) no Hoare annotation was computed. [2022-11-16 15:54:25,667 INFO L899 garLoopResultBuilder]: For program point L284-1(lines 283 302) no Hoare annotation was computed. [2022-11-16 15:54:25,667 INFO L895 garLoopResultBuilder]: At program point L346(lines 346 354) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~pumpRunning~0 0)) (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= |timeShift_processEnvironment_~tmp~2#1| 1)) (< |old(~waterLevel~0)| 2) .cse0 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0))) [2022-11-16 15:54:25,667 INFO L895 garLoopResultBuilder]: At program point L342(lines 342 359) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0))) (let ((.cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse2 (= 0 ~systemActive~0))) (and (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (or .cse0 (and (not .cse1) (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))))) (< |old(~waterLevel~0)| 2) .cse2 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse2)))) [2022-11-16 15:54:25,667 INFO L899 garLoopResultBuilder]: For program point L512(lines 512 518) no Hoare annotation was computed. [2022-11-16 15:54:25,668 INFO L895 garLoopResultBuilder]: At program point L508(lines 508 521) the Hoare annotation is: (let ((.cse18 (= ~methaneLevelCritical~0 0))) (let ((.cse17 (= ~pumpRunning~0 1)) (.cse4 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 0)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not .cse18)) (.cse15 (= ~pumpRunning~0 0)) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse13 (and .cse15 .cse16)) (.cse12 (and (or .cse1 .cse18) (or .cse3 (not (= |old(~pumpRunning~0)| 1))))) (.cse14 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse8 (< |old(~waterLevel~0)| 2)) (.cse5 (= 0 ~systemActive~0)) (.cse9 (not (<= |old(~waterLevel~0)| 2))) (.cse11 (not (= ~methaneLevelCritical~0 1))) (.cse10 (not .cse4)) (.cse6 (and .cse15 .cse3)) (.cse7 (and .cse18 .cse17))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse1 .cse6 .cse7 .cse8 .cse5 .cse9) (or .cse0 .cse1 .cse10 .cse2 .cse11 .cse5) (or .cse8 .cse12 .cse3 .cse4 .cse5 .cse9) (or .cse0 .cse1 .cse13 .cse2 .cse5) (or (and .cse1 .cse14) .cse13 .cse8 .cse12 .cse5 .cse9) (or (and .cse15 .cse14 (= |timeShift_processEnvironment_~tmp~2#1| 1)) .cse8 .cse5 .cse9 (and .cse16 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse11) (or (and .cse4 .cse17) (and .cse10 .cse15)) (or .cse6 .cse7))))))) [2022-11-16 15:54:25,668 INFO L895 garLoopResultBuilder]: At program point L508-1(lines 500 524) the Hoare annotation is: (let ((.cse7 (= ~methaneLevelCritical~0 0))) (let ((.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not .cse7)) (.cse2 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~6#1| 0))) (let ((.cse14 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not .cse2)) (.cse8 (= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~2#1| 0)) (.cse9 (< |old(~waterLevel~0)| 2)) (.cse17 (and (or .cse10 .cse7) (or .cse6 (not (= |old(~pumpRunning~0)| 1))))) (.cse11 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse13 (not (<= |old(~waterLevel~0)| 2))) (.cse15 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (= ~pumpRunning~0 0)) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse16 (not (<= 1 |old(~waterLevel~0)|))) (.cse12 (= 0 ~systemActive~0))) (and (let ((.cse1 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse14))) (or (let ((.cse3 (= ~pumpRunning~0 1))) (and .cse0 .cse1 (or (and .cse2 .cse3) (and .cse4 .cse5)) (or (and .cse5 .cse6) (and .cse7 .cse3)) (or .cse7 (not (= |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#t~ret13#1| 0))) (or .cse7 (not (= |isMethaneLevelCritical_#res| 0))))) (and .cse4 .cse5 .cse8 .cse6 .cse0 .cse1) .cse9 (and .cse10 .cse5 .cse11 (= |timeShift_processEnvironment_~tmp~2#1| 1)) .cse12 .cse13)) (or .cse15 .cse10 .cse16 .cse6 .cse2 .cse12) (or .cse15 .cse10 .cse16 .cse14 (and .cse4 .cse8) .cse12) (or .cse11 .cse8 .cse9 .cse17 .cse12 .cse13) (or .cse9 .cse17 .cse6 (and .cse11 .cse2) .cse12 .cse13) (or .cse15 .cse10 (and .cse5 .cse0) .cse16 .cse12))))) [2022-11-16 15:54:25,669 INFO L895 garLoopResultBuilder]: At program point L54(line 54) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0))) [2022-11-16 15:54:25,669 INFO L895 garLoopResultBuilder]: At program point L352(line 352) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0))) [2022-11-16 15:54:25,669 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 280 303) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse1 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|)) .cse1))) [2022-11-16 15:54:25,669 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 280 303) no Hoare annotation was computed. [2022-11-16 15:54:25,670 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-16 15:54:25,670 INFO L895 garLoopResultBuilder]: At program point L357(line 357) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 .cse1) .cse2 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) (and .cse0 .cse1) (not (<= 1 |old(~waterLevel~0)|)) .cse2))) [2022-11-16 15:54:25,670 INFO L895 garLoopResultBuilder]: At program point L357-1(lines 338 362) the Hoare annotation is: (let ((.cse9 (= ~methaneLevelCritical~0 0))) (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse8 (not .cse9))) (let ((.cse1 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (and .cse7 (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 1))) (or (and .cse0 .cse8) (and .cse9 (= ~pumpRunning~0 1))))) (.cse3 (< |old(~waterLevel~0)| 2)) (.cse4 (= 0 ~systemActive~0)) (.cse5 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and .cse0 .cse1 (= |timeShift_processEnvironment_~tmp~2#1| 1)) .cse2 .cse3 .cse4 .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse6 (and .cse0 .cse7) (not (<= 1 |old(~waterLevel~0)|)) .cse4) (or .cse1 .cse3 .cse8 (not (= |old(~pumpRunning~0)| 1)) .cse4 .cse5) (or .cse6 .cse2 .cse3 .cse4 .cse5))))) [2022-11-16 15:54:25,670 INFO L899 garLoopResultBuilder]: For program point L291-1(lines 291 297) no Hoare annotation was computed. [2022-11-16 15:54:25,670 INFO L899 garLoopResultBuilder]: For program point L193(line 193) no Hoare annotation was computed. [2022-11-16 15:54:25,671 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 172 201) no Hoare annotation was computed. [2022-11-16 15:54:25,671 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 172 201) the Hoare annotation is: true [2022-11-16 15:54:25,671 INFO L899 garLoopResultBuilder]: For program point L186(lines 186 190) no Hoare annotation was computed. [2022-11-16 15:54:25,671 INFO L902 garLoopResultBuilder]: At program point L186-1(lines 186 190) the Hoare annotation is: true [2022-11-16 15:54:25,671 INFO L902 garLoopResultBuilder]: At program point L182-2(lines 182 196) the Hoare annotation is: true [2022-11-16 15:54:25,671 INFO L902 garLoopResultBuilder]: At program point L178(line 178) the Hoare annotation is: true [2022-11-16 15:54:25,671 INFO L899 garLoopResultBuilder]: For program point L178-1(line 178) no Hoare annotation was computed. [2022-11-16 15:54:25,672 INFO L902 garLoopResultBuilder]: At program point L197(lines 172 201) the Hoare annotation is: true [2022-11-16 15:54:25,672 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 105 113) the Hoare annotation is: true [2022-11-16 15:54:25,672 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 105 113) no Hoare annotation was computed. [2022-11-16 15:54:25,672 INFO L902 garLoopResultBuilder]: At program point L258-2(lines 258 265) the Hoare annotation is: true [2022-11-16 15:54:25,672 INFO L899 garLoopResultBuilder]: For program point L556(lines 556 562) no Hoare annotation was computed. [2022-11-16 15:54:25,672 INFO L895 garLoopResultBuilder]: At program point L556-1(lines 556 562) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2) .cse1) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 (<= 1 ~waterLevel~0) .cse1))) [2022-11-16 15:54:25,673 INFO L895 garLoopResultBuilder]: At program point L581(lines 536 583) the Hoare annotation is: (let ((.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= ~waterLevel~0 1) .cse1 (<= 1 ~waterLevel~0) .cse2) (and (<= 2 ~waterLevel~0) .cse1 (<= ~waterLevel~0 2) (let ((.cse3 (= ~methaneLevelCritical~0 0))) (or (and .cse0 (not .cse3)) (and .cse3 (= ~pumpRunning~0 1)))) .cse2))) [2022-11-16 15:54:25,673 INFO L895 garLoopResultBuilder]: At program point L548(line 548) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse1 (<= 2 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2)) (.cse5 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 (not .cse2) .cse3 .cse4 .cse5) (and .cse0 (<= ~waterLevel~0 1) .cse3 (<= 1 ~waterLevel~0) .cse5) (and .cse2 .cse1 .cse3 .cse4 .cse5 (= ~pumpRunning~0 1)))) [2022-11-16 15:54:25,673 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-16 15:54:25,673 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 15:54:25,673 INFO L895 garLoopResultBuilder]: At program point L574-2(lines 566 579) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2) .cse1) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 (<= 1 ~waterLevel~0) .cse1))) [2022-11-16 15:54:25,674 INFO L899 garLoopResultBuilder]: For program point L537(lines 536 583) no Hoare annotation was computed. [2022-11-16 15:54:25,674 INFO L895 garLoopResultBuilder]: At program point L558(line 558) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (not (= 0 ~systemActive~0)))) (or (and (<= 2 ~waterLevel~0) .cse0 (<= ~waterLevel~0 2) .cse1) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 (<= 1 ~waterLevel~0) .cse1))) [2022-11-16 15:54:25,674 INFO L902 garLoopResultBuilder]: At program point L587(lines 526 591) the Hoare annotation is: true [2022-11-16 15:54:25,674 INFO L899 garLoopResultBuilder]: For program point L546(lines 546 552) no Hoare annotation was computed. [2022-11-16 15:54:25,674 INFO L899 garLoopResultBuilder]: For program point L546-1(lines 546 552) no Hoare annotation was computed. [2022-11-16 15:54:25,674 INFO L895 garLoopResultBuilder]: At program point L584(lines 535 585) the Hoare annotation is: false [2022-11-16 15:54:25,675 INFO L895 garLoopResultBuilder]: At program point L258(lines 258 265) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-11-16 15:54:25,675 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 312 336) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 1 ~waterLevel~0)) (not (<= ~waterLevel~0 1)) .cse2) (or .cse0 .cse1 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse2))) [2022-11-16 15:54:25,675 INFO L899 garLoopResultBuilder]: For program point L320(lines 320 328) no Hoare annotation was computed. [2022-11-16 15:54:25,675 INFO L895 garLoopResultBuilder]: At program point L316(lines 316 333) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 1 ~waterLevel~0)) (not (<= ~waterLevel~0 1)) .cse2) (or .cse0 .cse1 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse2))) [2022-11-16 15:54:25,675 INFO L895 garLoopResultBuilder]: At program point L331(line 331) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= 1 ~waterLevel~0)) (not (<= ~waterLevel~0 1)) .cse1) (or .cse0 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse1))) [2022-11-16 15:54:25,676 INFO L899 garLoopResultBuilder]: For program point L331-1(lines 312 336) no Hoare annotation was computed. [2022-11-16 15:54:25,676 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 312 336) no Hoare annotation was computed. [2022-11-16 15:54:25,676 INFO L895 garLoopResultBuilder]: At program point L402(line 402) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= 1 ~waterLevel~0)) (not (<= ~waterLevel~0 1)) .cse1) (or (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 1)) .cse0 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse1))) [2022-11-16 15:54:25,676 INFO L895 garLoopResultBuilder]: At program point L402-1(line 402) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= 1 ~waterLevel~0)) (not (<= ~waterLevel~0 1)) .cse1) (or .cse0 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#t~ret13#1| ~methaneLevelCritical~0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 1)) (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse1))) [2022-11-16 15:54:25,676 INFO L895 garLoopResultBuilder]: At program point L326(line 326) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (< ~waterLevel~0 2) .cse1) (or .cse0 (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0)) (not (<= ~waterLevel~0 1)) .cse1))) [2022-11-16 15:54:25,677 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 81 92) no Hoare annotation was computed. [2022-11-16 15:54:25,677 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 81 92) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0))) (and (or (let ((.cse1 (= ~methaneLevelCritical~0 0))) (and (or .cse0 .cse1) (or (not .cse1) (not (= ~pumpRunning~0 1))))) (< |old(~waterLevel~0)| 2) .cse2 .cse3 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse2 .cse3))) [2022-11-16 15:54:25,680 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 15:54:25,682 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 15:54:25,733 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 03:54:25 BoogieIcfgContainer [2022-11-16 15:54:25,733 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 15:54:25,734 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 15:54:25,734 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 15:54:25,734 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 15:54:25,735 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 03:52:41" (3/4) ... [2022-11-16 15:54:25,738 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 15:54:25,752 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 15:54:25,752 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 15:54:25,752 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 15:54:25,752 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 15:54:25,752 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-16 15:54:25,753 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 15:54:25,753 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 15:54:25,760 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 81 nodes and edges [2022-11-16 15:54:25,761 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 26 nodes and edges [2022-11-16 15:54:25,761 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-16 15:54:25,762 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 15:54:25,762 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 15:54:25,765 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 15:54:25,766 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 15:54:25,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2 || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) [2022-11-16 15:54:25,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) [2022-11-16 15:54:25,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && tmp == 1) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive)) && (((((\old(waterLevel) == waterLevel + 1 || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) [2022-11-16 15:54:25,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= waterLevel)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || waterLevel < 2) || 0 == systemActive) [2022-11-16 15:54:25,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(methaneLevelCritical == 0))) || (methaneLevelCritical == 0 && pumpRunning == 1)) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(tmp == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 1)) || 0 == systemActive)) && (((((\old(waterLevel) < 2 || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive)) && ((((((!(\old(pumpRunning) == 0) && \old(waterLevel) == waterLevel + 1) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && tmp == 1) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((tmp == 0 && pumpRunning == 1) || (!(tmp == 0) && pumpRunning == 0))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) [2022-11-16 15:54:25,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((tmp == 0 && pumpRunning == 1) || (!(tmp == 0) && pumpRunning == 0))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1))) && (methaneLevelCritical == 0 || !(aux-isMethaneLevelCritical()-aux == 0))) && (methaneLevelCritical == 0 || !(\result == 0))) || (((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(methaneLevelCritical == 0)) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1)))) || \old(waterLevel) < 2) || (((!(\old(pumpRunning) == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive)) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 1)) || (!(tmp == 0) && tmp___0 == 0)) || 0 == systemActive)) && (((((\old(waterLevel) == waterLevel + 1 || tmp___0 == 0) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((\old(waterLevel) < 2 || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || (\old(waterLevel) == waterLevel + 1 && tmp == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) [2022-11-16 15:54:25,798 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && aux-isMethaneLevelCritical()-aux == methaneLevelCritical) && tmp == 1)) || !(waterLevel <= 2)) || waterLevel < 2) || 0 == systemActive) [2022-11-16 15:54:25,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((\old(waterLevel) < 2 || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || 0 == systemActive) [2022-11-16 15:54:25,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == \old(pumpRunning) && !(pumpRunning == 0)) && \old(waterLevel) == waterLevel + 1) && tmp == 1) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || 0 == systemActive) [2022-11-16 15:54:25,825 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/witness.graphml [2022-11-16 15:54:25,826 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 15:54:25,826 INFO L158 Benchmark]: Toolchain (without parser) took 105837.65ms. Allocated memory was 134.2MB in the beginning and 610.3MB in the end (delta: 476.1MB). Free memory was 96.9MB in the beginning and 472.8MB in the end (delta: -376.0MB). Peak memory consumption was 100.7MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,827 INFO L158 Benchmark]: CDTParser took 0.32ms. Allocated memory is still 134.2MB. Free memory is still 113.9MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 15:54:25,827 INFO L158 Benchmark]: CACSL2BoogieTranslator took 558.51ms. Allocated memory is still 134.2MB. Free memory was 96.6MB in the beginning and 100.4MB in the end (delta: -3.8MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,827 INFO L158 Benchmark]: Boogie Procedure Inliner took 59.98ms. Allocated memory is still 134.2MB. Free memory was 100.4MB in the beginning and 98.0MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,828 INFO L158 Benchmark]: Boogie Preprocessor took 32.20ms. Allocated memory is still 134.2MB. Free memory was 98.0MB in the beginning and 96.3MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,828 INFO L158 Benchmark]: RCFGBuilder took 800.31ms. Allocated memory is still 134.2MB. Free memory was 96.3MB in the beginning and 67.9MB in the end (delta: 28.4MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,829 INFO L158 Benchmark]: TraceAbstraction took 104282.45ms. Allocated memory was 134.2MB in the beginning and 610.3MB in the end (delta: 476.1MB). Free memory was 67.0MB in the beginning and 478.1MB in the end (delta: -411.1MB). Peak memory consumption was 334.1MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,829 INFO L158 Benchmark]: Witness Printer took 91.92ms. Allocated memory is still 610.3MB. Free memory was 478.1MB in the beginning and 472.8MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 15:54:25,831 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.32ms. Allocated memory is still 134.2MB. Free memory is still 113.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 558.51ms. Allocated memory is still 134.2MB. Free memory was 96.6MB in the beginning and 100.4MB in the end (delta: -3.8MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 59.98ms. Allocated memory is still 134.2MB. Free memory was 100.4MB in the beginning and 98.0MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 32.20ms. Allocated memory is still 134.2MB. Free memory was 98.0MB in the beginning and 96.3MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 800.31ms. Allocated memory is still 134.2MB. Free memory was 96.3MB in the beginning and 67.9MB in the end (delta: 28.4MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. * TraceAbstraction took 104282.45ms. Allocated memory was 134.2MB in the beginning and 610.3MB in the end (delta: 476.1MB). Free memory was 67.0MB in the beginning and 478.1MB in the end (delta: -411.1MB). Peak memory consumption was 334.1MB. Max. memory is 16.1GB. * Witness Printer took 91.92ms. Allocated memory is still 610.3MB. Free memory was 478.1MB in the beginning and 472.8MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 57 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 104.2s, OverallIterations: 9, TraceHistogramMax: 6, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 9.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2437 SdHoareTripleChecker+Valid, 4.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2417 mSDsluCounter, 1863 SdHoareTripleChecker+Invalid, 3.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1434 mSDsCounter, 1653 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4411 IncrementalHoareTripleChecker+Invalid, 6064 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1653 mSolverCounterUnsat, 429 mSDtfsCounter, 4411 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 855 GetRequests, 537 SyntacticMatches, 32 SemanticMatches, 286 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10675 ImplicationChecksByTransitivity, 63.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1095occurred in iteration=8, InterpolantAutomatonStates: 154, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 9 MinimizatonAttempts, 431 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 35 LocationsWithAnnotation, 1613 PreInvPairs, 1794 NumberOfFragments, 1590 HoareAnnotationTreeSize, 1613 FomulaSimplifications, 5073 FormulaSimplificationTreeSizeReduction, 0.5s HoareSimplificationTime, 35 FomulaSimplificationsInter, 18059 FormulaSimplificationTreeSizeReductionInter, 4.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 6.9s InterpolantComputationTime, 594 NumberOfCodeBlocks, 594 NumberOfCodeBlocksAsserted, 12 NumberOfCheckSat, 795 ConstructedInterpolants, 0 QuantifiedInterpolants, 3164 SizeOfPredicates, 42 NumberOfNonLiveVariables, 1385 ConjunctsInSsa, 112 ConjunctsInUnsatCore, 15 InterpolantComputations, 6 PerfectInterpolantSequences, 384/531 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 338]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && tmp == 1) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive)) && (((((\old(waterLevel) == waterLevel + 1 || \old(waterLevel) < 2) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || ((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 508]: Loop Invariant Derived loop invariant: ((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && !(methaneLevelCritical == 0))) || (methaneLevelCritical == 0 && pumpRunning == 1)) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(tmp == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 1)) || 0 == systemActive)) && (((((\old(waterLevel) < 2 || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive)) && ((((((!(\old(pumpRunning) == 0) && \old(waterLevel) == waterLevel + 1) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && tmp == 1) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((tmp == 0 && pumpRunning == 1) || (!(tmp == 0) && pumpRunning == 0))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1)))) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: ((\old(waterLevel) < 2 || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || 0 == systemActive) - InvariantResult [Line: 535]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 258]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 556]: Loop Invariant Derived loop invariant: (((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) && !(0 == systemActive)) || ((((pumpRunning == 0 && waterLevel <= 1) && splverifierCounter == 0) && 1 <= waterLevel) && !(0 == systemActive)) - InvariantResult [Line: 280]: Loop Invariant Derived loop invariant: (((\old(waterLevel) < 2 || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) - InvariantResult [Line: 172]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 402]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && aux-isMethaneLevelCritical()-aux == methaneLevelCritical) && tmp == 1)) || !(waterLevel <= 2)) || waterLevel < 2) || 0 == systemActive) - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 342]: Loop Invariant Derived loop invariant: ((((pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 <= waterLevel)) || !(waterLevel <= 1)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(waterLevel <= 2)) || waterLevel < 2) || 0 == systemActive) - InvariantResult [Line: 526]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 346]: Loop Invariant Derived loop invariant: ((((((pumpRunning == \old(pumpRunning) && !(pumpRunning == 0)) && \old(waterLevel) == waterLevel + 1) && tmp == 1) || \old(waterLevel) < 2) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || 0 == systemActive) - InvariantResult [Line: 258]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && tmp == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 536]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && waterLevel <= 1) && splverifierCounter == 0) && 1 <= waterLevel) && !(0 == systemActive)) || ((((2 <= waterLevel && splverifierCounter == 0) && waterLevel <= 2) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1))) && !(0 == systemActive)) - InvariantResult [Line: 500]: Loop Invariant Derived loop invariant: ((((((((((((((\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1))) && ((tmp == 0 && pumpRunning == 1) || (!(tmp == 0) && pumpRunning == 0))) && ((pumpRunning == 0 && !(methaneLevelCritical == 0)) || (methaneLevelCritical == 0 && pumpRunning == 1))) && (methaneLevelCritical == 0 || !(aux-isMethaneLevelCritical()-aux == 0))) && (methaneLevelCritical == 0 || !(\result == 0))) || (((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(methaneLevelCritical == 0)) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || !(methaneLevelCritical == 1)))) || \old(waterLevel) < 2) || (((!(\old(pumpRunning) == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp == 1)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 0)) || tmp == 0) || 0 == systemActive)) && (((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(methaneLevelCritical == 1)) || (!(tmp == 0) && tmp___0 == 0)) || 0 == systemActive)) && (((((\old(waterLevel) == waterLevel + 1 || tmp___0 == 0) || \old(waterLevel) < 2) || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && (((((\old(waterLevel) < 2 || ((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || !(\old(pumpRunning) == 1)))) || !(methaneLevelCritical == 0)) || (\old(waterLevel) == waterLevel + 1 && tmp == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || 0 == systemActive) RESULT: Ultimate proved your program to be correct! [2022-11-16 15:54:25,866 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_4ae5ddc3-e730-45d5-8397-90692f8c0a86/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE