./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e04fb08f Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash ae631a30e0cfb00652c35b082fd4038988aa5f3b2e1b026ceeb94d0624c45642 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-e04fb08 [2022-11-16 16:07:38,497 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-16 16:07:38,499 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-16 16:07:38,533 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-16 16:07:38,534 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-16 16:07:38,538 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-16 16:07:38,540 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-16 16:07:38,542 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-16 16:07:38,544 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-16 16:07:38,545 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-16 16:07:38,546 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-16 16:07:38,547 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-16 16:07:38,547 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-16 16:07:38,548 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-16 16:07:38,550 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-16 16:07:38,551 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-16 16:07:38,552 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-16 16:07:38,553 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-16 16:07:38,560 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-16 16:07:38,570 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-16 16:07:38,573 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-16 16:07:38,574 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-16 16:07:38,577 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-16 16:07:38,579 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-16 16:07:38,587 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-16 16:07:38,588 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-16 16:07:38,588 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-16 16:07:38,590 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-16 16:07:38,590 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-16 16:07:38,591 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-16 16:07:38,592 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-16 16:07:38,593 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-16 16:07:38,593 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-16 16:07:38,594 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-16 16:07:38,595 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-16 16:07:38,596 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-16 16:07:38,596 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-16 16:07:38,597 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-16 16:07:38,597 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-16 16:07:38,598 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-16 16:07:38,599 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-16 16:07:38,599 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-16 16:07:38,644 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-16 16:07:38,645 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-16 16:07:38,645 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-16 16:07:38,646 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-16 16:07:38,647 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-16 16:07:38,647 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-16 16:07:38,647 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-16 16:07:38,647 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-16 16:07:38,647 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-16 16:07:38,648 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-16 16:07:38,649 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-16 16:07:38,649 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-16 16:07:38,649 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-16 16:07:38,649 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-16 16:07:38,650 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-16 16:07:38,650 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-16 16:07:38,650 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-16 16:07:38,650 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-16 16:07:38,651 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-16 16:07:38,651 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-16 16:07:38,651 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-16 16:07:38,652 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-16 16:07:38,652 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-16 16:07:38,653 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-16 16:07:38,653 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-16 16:07:38,654 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-16 16:07:38,654 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-16 16:07:38,654 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-16 16:07:38,654 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-16 16:07:38,654 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-16 16:07:38,655 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-16 16:07:38,655 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-16 16:07:38,656 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 16:07:38,656 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-16 16:07:38,656 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-16 16:07:38,656 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-16 16:07:38,657 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-16 16:07:38,657 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-16 16:07:38,657 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-16 16:07:38,657 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-16 16:07:38,657 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-16 16:07:38,658 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> ae631a30e0cfb00652c35b082fd4038988aa5f3b2e1b026ceeb94d0624c45642 [2022-11-16 16:07:38,960 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-16 16:07:38,989 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-16 16:07:38,992 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-16 16:07:38,993 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-16 16:07:38,994 INFO L275 PluginConnector]: CDTParser initialized [2022-11-16 16:07:38,995 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/../../sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c [2022-11-16 16:07:39,073 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/data/f7355ae7d/89fd2a6d68c5434cb461b98b2b8fde18/FLAG863693395 [2022-11-16 16:07:39,593 INFO L306 CDTParser]: Found 1 translation units. [2022-11-16 16:07:39,594 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c [2022-11-16 16:07:39,605 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/data/f7355ae7d/89fd2a6d68c5434cb461b98b2b8fde18/FLAG863693395 [2022-11-16 16:07:39,922 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/data/f7355ae7d/89fd2a6d68c5434cb461b98b2b8fde18 [2022-11-16 16:07:39,925 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-16 16:07:39,926 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-16 16:07:39,928 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-16 16:07:39,928 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-16 16:07:39,932 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-16 16:07:39,932 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 04:07:39" (1/1) ... [2022-11-16 16:07:39,933 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@4a19482d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:39, skipping insertion in model container [2022-11-16 16:07:39,934 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.11 04:07:39" (1/1) ... [2022-11-16 16:07:39,941 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-16 16:07:39,980 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-16 16:07:40,282 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c[13037,13050] [2022-11-16 16:07:40,322 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 16:07:40,332 INFO L203 MainTranslator]: Completed pre-run [2022-11-16 16:07:40,411 WARN L229 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/sv-benchmarks/c/product-lines/minepump_spec3_product58.cil.c[13037,13050] [2022-11-16 16:07:40,434 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-16 16:07:40,467 INFO L208 MainTranslator]: Completed translation [2022-11-16 16:07:40,467 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40 WrapperNode [2022-11-16 16:07:40,467 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-16 16:07:40,469 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-16 16:07:40,469 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-16 16:07:40,469 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-16 16:07:40,477 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,500 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,532 INFO L138 Inliner]: procedures = 57, calls = 158, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 283 [2022-11-16 16:07:40,533 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-16 16:07:40,534 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-16 16:07:40,534 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-16 16:07:40,534 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-16 16:07:40,544 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,544 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,547 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,548 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,553 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,559 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,561 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,562 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,565 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-16 16:07:40,566 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-16 16:07:40,566 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-16 16:07:40,566 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-16 16:07:40,567 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (1/1) ... [2022-11-16 16:07:40,579 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-16 16:07:40,592 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:07:40,608 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-16 16:07:40,611 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-16 16:07:40,648 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-16 16:07:40,648 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-16 16:07:40,648 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-16 16:07:40,649 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-11-16 16:07:40,649 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-11-16 16:07:40,649 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-16 16:07:40,649 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-16 16:07:40,649 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-16 16:07:40,650 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-16 16:07:40,650 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 16:07:40,650 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 16:07:40,650 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-16 16:07:40,650 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-16 16:07:40,650 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-16 16:07:40,651 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-16 16:07:40,651 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-16 16:07:40,651 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-16 16:07:40,651 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-16 16:07:40,786 INFO L235 CfgBuilder]: Building ICFG [2022-11-16 16:07:40,789 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-16 16:07:41,218 INFO L276 CfgBuilder]: Performing block encoding [2022-11-16 16:07:41,369 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-16 16:07:41,369 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-16 16:07:41,372 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 04:07:41 BoogieIcfgContainer [2022-11-16 16:07:41,372 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-16 16:07:41,374 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-16 16:07:41,374 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-16 16:07:41,380 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-16 16:07:41,381 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.11 04:07:39" (1/3) ... [2022-11-16 16:07:41,381 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@760135c0 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 04:07:41, skipping insertion in model container [2022-11-16 16:07:41,381 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.11 04:07:40" (2/3) ... [2022-11-16 16:07:41,382 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@760135c0 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.11 04:07:41, skipping insertion in model container [2022-11-16 16:07:41,382 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 04:07:41" (3/3) ... [2022-11-16 16:07:41,383 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product58.cil.c [2022-11-16 16:07:41,429 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-16 16:07:41,430 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-16 16:07:41,490 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-16 16:07:41,498 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@192c6254, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-16 16:07:41,499 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-16 16:07:41,504 INFO L276 IsEmpty]: Start isEmpty. Operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-16 16:07:41,513 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 18 [2022-11-16 16:07:41,514 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:41,515 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:41,515 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:41,521 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:41,522 INFO L85 PathProgramCache]: Analyzing trace with hash -1778790351, now seen corresponding path program 1 times [2022-11-16 16:07:41,533 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:41,534 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [262544347] [2022-11-16 16:07:41,534 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:41,535 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:41,702 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:41,838 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:41,839 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:41,839 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [262544347] [2022-11-16 16:07:41,840 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [262544347] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:41,841 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:41,841 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-16 16:07:41,843 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1610108962] [2022-11-16 16:07:41,844 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:41,850 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-16 16:07:41,852 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:41,891 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-16 16:07:41,892 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 16:07:41,895 INFO L87 Difference]: Start difference. First operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,025 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:42,025 INFO L93 Difference]: Finished difference Result 114 states and 155 transitions. [2022-11-16 16:07:42,028 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-16 16:07:42,029 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 17 [2022-11-16 16:07:42,030 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:42,050 INFO L225 Difference]: With dead ends: 114 [2022-11-16 16:07:42,051 INFO L226 Difference]: Without dead ends: 53 [2022-11-16 16:07:42,055 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-16 16:07:42,059 INFO L413 NwaCegarLoop]: 56 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 56 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:42,060 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 56 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 16:07:42,077 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-16 16:07:42,105 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-16 16:07:42,107 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3235294117647058) internal successors, (45), 41 states have internal predecessors, (45), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-16 16:07:42,116 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 68 transitions. [2022-11-16 16:07:42,118 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 68 transitions. Word has length 17 [2022-11-16 16:07:42,119 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:42,119 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 68 transitions. [2022-11-16 16:07:42,120 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,121 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 68 transitions. [2022-11-16 16:07:42,127 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 19 [2022-11-16 16:07:42,128 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:42,129 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:42,129 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-16 16:07:42,129 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:42,131 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:42,131 INFO L85 PathProgramCache]: Analyzing trace with hash 942296326, now seen corresponding path program 1 times [2022-11-16 16:07:42,131 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:42,132 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1695231409] [2022-11-16 16:07:42,132 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:42,133 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:42,173 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:42,282 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:42,282 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:42,282 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1695231409] [2022-11-16 16:07:42,283 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1695231409] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:42,283 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:42,283 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 16:07:42,283 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1276223522] [2022-11-16 16:07:42,284 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:42,285 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 16:07:42,285 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:42,286 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 16:07:42,286 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:42,286 INFO L87 Difference]: Start difference. First operand 53 states and 68 transitions. Second operand has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,359 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:42,360 INFO L93 Difference]: Finished difference Result 83 states and 107 transitions. [2022-11-16 16:07:42,360 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 16:07:42,361 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 18 [2022-11-16 16:07:42,361 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:42,365 INFO L225 Difference]: With dead ends: 83 [2022-11-16 16:07:42,366 INFO L226 Difference]: Without dead ends: 45 [2022-11-16 16:07:42,371 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:42,373 INFO L413 NwaCegarLoop]: 42 mSDtfsCounter, 7 mSDsluCounter, 33 mSDsCounter, 0 mSdLazyCounter, 27 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 75 SdHoareTripleChecker+Invalid, 27 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 27 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:42,377 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 75 Invalid, 27 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 27 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 16:07:42,378 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 45 states. [2022-11-16 16:07:42,384 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 45 to 45. [2022-11-16 16:07:42,384 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 45 states, 29 states have (on average 1.3448275862068966) internal successors, (39), 36 states have internal predecessors, (39), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-16 16:07:42,385 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 45 states to 45 states and 57 transitions. [2022-11-16 16:07:42,385 INFO L78 Accepts]: Start accepts. Automaton has 45 states and 57 transitions. Word has length 18 [2022-11-16 16:07:42,386 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:42,386 INFO L495 AbstractCegarLoop]: Abstraction has 45 states and 57 transitions. [2022-11-16 16:07:42,386 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,386 INFO L276 IsEmpty]: Start isEmpty. Operand 45 states and 57 transitions. [2022-11-16 16:07:42,390 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-11-16 16:07:42,390 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:42,390 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:42,390 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-16 16:07:42,391 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:42,391 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:42,391 INFO L85 PathProgramCache]: Analyzing trace with hash 1782950032, now seen corresponding path program 1 times [2022-11-16 16:07:42,391 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:42,392 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1682651321] [2022-11-16 16:07:42,392 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:42,393 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:42,428 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:42,720 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:42,721 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:42,721 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1682651321] [2022-11-16 16:07:42,721 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1682651321] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:42,721 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:42,722 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-16 16:07:42,722 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [317504558] [2022-11-16 16:07:42,722 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:42,722 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-16 16:07:42,723 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:42,723 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-16 16:07:42,723 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=8, Invalid=12, Unknown=0, NotChecked=0, Total=20 [2022-11-16 16:07:42,724 INFO L87 Difference]: Start difference. First operand 45 states and 57 transitions. Second operand has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,870 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:42,870 INFO L93 Difference]: Finished difference Result 153 states and 195 transitions. [2022-11-16 16:07:42,871 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-16 16:07:42,871 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 20 [2022-11-16 16:07:42,871 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:42,873 INFO L225 Difference]: With dead ends: 153 [2022-11-16 16:07:42,873 INFO L226 Difference]: Without dead ends: 110 [2022-11-16 16:07:42,874 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=18, Invalid=24, Unknown=0, NotChecked=0, Total=42 [2022-11-16 16:07:42,875 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 67 mSDsluCounter, 150 mSDsCounter, 0 mSdLazyCounter, 84 mSolverCounterSat, 5 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 203 SdHoareTripleChecker+Invalid, 89 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 5 IncrementalHoareTripleChecker+Valid, 84 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:42,875 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 203 Invalid, 89 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [5 Valid, 84 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 16:07:42,876 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 110 states. [2022-11-16 16:07:42,893 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 110 to 91. [2022-11-16 16:07:42,893 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 60 states have (on average 1.2666666666666666) internal successors, (76), 69 states have internal predecessors, (76), 16 states have call successors, (16), 12 states have call predecessors, (16), 14 states have return successors, (18), 15 states have call predecessors, (18), 16 states have call successors, (18) [2022-11-16 16:07:42,894 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 110 transitions. [2022-11-16 16:07:42,894 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 110 transitions. Word has length 20 [2022-11-16 16:07:42,895 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:42,895 INFO L495 AbstractCegarLoop]: Abstraction has 91 states and 110 transitions. [2022-11-16 16:07:42,895 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-16 16:07:42,895 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 110 transitions. [2022-11-16 16:07:42,896 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2022-11-16 16:07:42,897 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:42,897 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:42,897 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-16 16:07:42,897 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:42,898 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:42,898 INFO L85 PathProgramCache]: Analyzing trace with hash -1529217304, now seen corresponding path program 1 times [2022-11-16 16:07:42,898 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:42,898 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [889898786] [2022-11-16 16:07:42,898 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:42,899 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:42,917 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:43,020 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:43,021 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:43,040 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [889898786] [2022-11-16 16:07:43,040 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [889898786] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:43,040 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:43,040 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 16:07:43,041 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1194953914] [2022-11-16 16:07:43,041 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:43,043 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 16:07:43,043 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:43,044 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 16:07:43,044 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:43,044 INFO L87 Difference]: Start difference. First operand 91 states and 110 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 16:07:43,112 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:43,112 INFO L93 Difference]: Finished difference Result 180 states and 220 transitions. [2022-11-16 16:07:43,113 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 16:07:43,113 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 23 [2022-11-16 16:07:43,113 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:43,117 INFO L225 Difference]: With dead ends: 180 [2022-11-16 16:07:43,117 INFO L226 Difference]: Without dead ends: 91 [2022-11-16 16:07:43,118 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:43,120 INFO L413 NwaCegarLoop]: 40 mSDtfsCounter, 45 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 16 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 45 SdHoareTripleChecker+Valid, 40 SdHoareTripleChecker+Invalid, 16 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 16 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:43,121 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [45 Valid, 40 Invalid, 16 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 16 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 16:07:43,122 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 91 states. [2022-11-16 16:07:43,135 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 91 to 91. [2022-11-16 16:07:43,136 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 60 states have (on average 1.2333333333333334) internal successors, (74), 69 states have internal predecessors, (74), 16 states have call successors, (16), 12 states have call predecessors, (16), 14 states have return successors, (18), 15 states have call predecessors, (18), 16 states have call successors, (18) [2022-11-16 16:07:43,139 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 108 transitions. [2022-11-16 16:07:43,140 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 108 transitions. Word has length 23 [2022-11-16 16:07:43,140 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:43,140 INFO L495 AbstractCegarLoop]: Abstraction has 91 states and 108 transitions. [2022-11-16 16:07:43,140 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 16:07:43,141 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 108 transitions. [2022-11-16 16:07:43,142 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-11-16 16:07:43,142 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:43,142 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:43,142 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-16 16:07:43,142 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:43,143 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:43,143 INFO L85 PathProgramCache]: Analyzing trace with hash 542471680, now seen corresponding path program 1 times [2022-11-16 16:07:43,143 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:43,143 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1677638646] [2022-11-16 16:07:43,144 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:43,144 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:43,175 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:43,275 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:43,275 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:43,275 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1677638646] [2022-11-16 16:07:43,275 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1677638646] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:43,276 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:43,276 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-16 16:07:43,276 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1535229686] [2022-11-16 16:07:43,278 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:43,279 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-16 16:07:43,282 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:43,283 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-16 16:07:43,283 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:43,283 INFO L87 Difference]: Start difference. First operand 91 states and 108 transitions. Second operand has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 16:07:43,351 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:43,352 INFO L93 Difference]: Finished difference Result 169 states and 208 transitions. [2022-11-16 16:07:43,352 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-16 16:07:43,352 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 26 [2022-11-16 16:07:43,352 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:43,357 INFO L225 Difference]: With dead ends: 169 [2022-11-16 16:07:43,357 INFO L226 Difference]: Without dead ends: 126 [2022-11-16 16:07:43,360 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-16 16:07:43,361 INFO L413 NwaCegarLoop]: 52 mSDtfsCounter, 37 mSDsluCounter, 33 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 37 SdHoareTripleChecker+Valid, 85 SdHoareTripleChecker+Invalid, 35 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:43,363 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [37 Valid, 85 Invalid, 35 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-16 16:07:43,364 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 126 states. [2022-11-16 16:07:43,404 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 126 to 124. [2022-11-16 16:07:43,404 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 124 states, 83 states have (on average 1.2289156626506024) internal successors, (102), 92 states have internal predecessors, (102), 20 states have call successors, (20), 18 states have call predecessors, (20), 20 states have return successors, (26), 21 states have call predecessors, (26), 20 states have call successors, (26) [2022-11-16 16:07:43,405 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 124 states to 124 states and 148 transitions. [2022-11-16 16:07:43,406 INFO L78 Accepts]: Start accepts. Automaton has 124 states and 148 transitions. Word has length 26 [2022-11-16 16:07:43,406 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:43,406 INFO L495 AbstractCegarLoop]: Abstraction has 124 states and 148 transitions. [2022-11-16 16:07:43,406 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-16 16:07:43,407 INFO L276 IsEmpty]: Start isEmpty. Operand 124 states and 148 transitions. [2022-11-16 16:07:43,408 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2022-11-16 16:07:43,408 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:43,408 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:43,408 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-16 16:07:43,409 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:43,409 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:43,409 INFO L85 PathProgramCache]: Analyzing trace with hash -232290254, now seen corresponding path program 1 times [2022-11-16 16:07:43,409 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:43,410 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1242766627] [2022-11-16 16:07:43,410 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:43,410 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:43,441 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:43,914 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:43,914 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:43,914 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1242766627] [2022-11-16 16:07:43,914 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1242766627] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:07:43,914 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:07:43,914 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-11-16 16:07:43,915 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1080995098] [2022-11-16 16:07:43,915 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:07:43,915 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-16 16:07:43,915 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:07:43,916 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-16 16:07:43,916 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=22, Invalid=50, Unknown=0, NotChecked=0, Total=72 [2022-11-16 16:07:43,916 INFO L87 Difference]: Start difference. First operand 124 states and 148 transitions. Second operand has 9 states, 8 states have (on average 3.125) internal successors, (25), 8 states have internal predecessors, (25), 5 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-16 16:07:44,513 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:07:44,513 INFO L93 Difference]: Finished difference Result 371 states and 471 transitions. [2022-11-16 16:07:44,514 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-16 16:07:44,514 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 3.125) internal successors, (25), 8 states have internal predecessors, (25), 5 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 34 [2022-11-16 16:07:44,514 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:07:44,517 INFO L225 Difference]: With dead ends: 371 [2022-11-16 16:07:44,517 INFO L226 Difference]: Without dead ends: 295 [2022-11-16 16:07:44,518 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 36 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=70, Invalid=170, Unknown=0, NotChecked=0, Total=240 [2022-11-16 16:07:44,519 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 350 mSDsluCounter, 139 mSDsCounter, 0 mSdLazyCounter, 334 mSolverCounterSat, 172 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 362 SdHoareTripleChecker+Valid, 219 SdHoareTripleChecker+Invalid, 506 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 172 IncrementalHoareTripleChecker+Valid, 334 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-16 16:07:44,519 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [362 Valid, 219 Invalid, 506 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [172 Valid, 334 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-16 16:07:44,520 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 295 states. [2022-11-16 16:07:44,561 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 295 to 269. [2022-11-16 16:07:44,562 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 269 states, 184 states have (on average 1.2717391304347827) internal successors, (234), 202 states have internal predecessors, (234), 44 states have call successors, (44), 36 states have call predecessors, (44), 40 states have return successors, (61), 43 states have call predecessors, (61), 44 states have call successors, (61) [2022-11-16 16:07:44,571 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 269 states to 269 states and 339 transitions. [2022-11-16 16:07:44,571 INFO L78 Accepts]: Start accepts. Automaton has 269 states and 339 transitions. Word has length 34 [2022-11-16 16:07:44,571 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:07:44,572 INFO L495 AbstractCegarLoop]: Abstraction has 269 states and 339 transitions. [2022-11-16 16:07:44,572 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 3.125) internal successors, (25), 8 states have internal predecessors, (25), 5 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-16 16:07:44,572 INFO L276 IsEmpty]: Start isEmpty. Operand 269 states and 339 transitions. [2022-11-16 16:07:44,579 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-16 16:07:44,579 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:07:44,580 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:07:44,580 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-16 16:07:44,580 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:07:44,580 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:07:44,582 INFO L85 PathProgramCache]: Analyzing trace with hash 1779709984, now seen corresponding path program 1 times [2022-11-16 16:07:44,582 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:07:44,582 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [225817533] [2022-11-16 16:07:44,582 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:44,583 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:07:44,601 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:44,788 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 16:07:44,788 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:07:44,788 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [225817533] [2022-11-16 16:07:44,788 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [225817533] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 16:07:44,788 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [446568242] [2022-11-16 16:07:44,789 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:07:44,789 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:07:44,789 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:07:44,795 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 16:07:44,820 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-16 16:07:44,907 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:07:44,924 INFO L263 TraceCheckSpWp]: Trace formula consists of 357 conjuncts, 35 conjunts are in the unsatisfiable core [2022-11-16 16:07:44,929 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 16:07:45,178 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:07:45,178 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 16:07:45,638 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 16:07:45,638 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [446568242] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 16:07:45,639 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [252636803] [2022-11-16 16:07:45,657 INFO L159 IcfgInterpreter]: Started Sifa with 34 locations of interest [2022-11-16 16:07:45,657 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 16:07:45,661 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 16:07:45,666 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 16:07:45,666 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 16:07:47,578 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 294 for LOIs [2022-11-16 16:07:47,656 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 295 for LOIs [2022-11-16 16:07:52,987 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 292 for LOIs [2022-11-16 16:07:53,793 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 45 for LOIs [2022-11-16 16:07:53,805 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 16:08:41,736 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '3105#(and (= (select |#length| 15) 25) (= (select (select |#memory_int| 19) 0) 79) (= (select (select |#memory_int| 17) 6) 0) (= 9 (select |#length| 5)) (= (select |#length| 9) 21) (= 30 (select |#length| 7)) (= 1 (select |#valid| 5)) (= (select |#length| 3) 12) (= 2 (select |#length| 20)) (= (select |#valid| 15) 1) (= (select (select |#memory_int| 22) 0) 79) (= 5 (select |#length| 18)) (= (select |#valid| 26) 1) (= (select (select |#memory_int| 27) 2) 0) (= (select (select |#memory_int| 26) 3) 0) (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (= (select |#valid| 9) 1) (= 13 (select |#length| 16)) (= (select |#length| 12) 25) (= (select (select |#memory_int| 18) 2) 73) (= (select |#length| 28) 2) (= (select |#valid| 11) 1) (= (select |#valid| 27) 1) (= 30 (select |#length| 4)) (= (select |#length| 22) 3) (= 4 (select |#length| 26)) (= 102 (select (select |#memory_int| 23) 1)) (= 31 (select |#length| 2)) (= ~head~0.offset 0) (= (select |#length| 21) 13) (= (select |#length| 27) 3) (<= 1 ~systemActive~0) (= 2 (select |#length| 1)) (= (select |#length| 8) 9) (= 84 (select (select |#memory_int| 18) 3)) (= 41 (select (select |#memory_int| 27) 0)) (= (select |#valid| 3) 1) (= (select |#length| 19) 3) (= (select |#valid| 7) 1) (= |timeShift_getWaterLevel_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|) (= (select |#valid| 18) 1) (<= |#NULL.offset| 0) (= 0 |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (= (select |#valid| 22) 1) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~11#1|) (= 30 (select |#length| 13)) (= 117 (select (select |#memory_int| 24) 2)) (= |old(~pumpRunning~0)| 0) (= (select |#valid| 24) 1) (= 30 (select |#length| 10)) (= (select (select |#memory_int| 19) 2) 0) (= 3 (select |#length| 25)) (= (select |#valid| 12) 1) (= 82 (select (select |#memory_int| 18) 1)) (= (select (select |#memory_int| 25) 1) 110) (= (select |#valid| 28) 1) (= (select (select |#memory_int| 25) 2) 0) (= 102 (select (select |#memory_int| 23) 2)) (= (select (select |#memory_int| 28) 1) 0) (<= ~methaneLevelCritical~0 0) (= (select |#valid| 4) 1) (= |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1| 0) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~11#1|) (<= 0 ~head~0.base) (= (select (select |#memory_int| 22) 2) 0) (= (select |#valid| 1) 1) (= (select |#valid| 20) 1) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (= (select |#length| 6) 21) (= (select |#valid| 21) 1) (= 7 (select |#length| 24)) (= 58 (select (select |#memory_int| 24) 5)) (= (select (select |#memory_int| 24) 1) 80) (= (select (select |#memory_int| 26) 2) 102) (= (select (select |#memory_int| 24) 6) 0) (<= 0 ~methaneLevelCritical~0) (= (select (select |#memory_int| 18) 4) 0) (= (select |#valid| 14) 1) (= 109 (select (select |#memory_int| 24) 3)) (= |old(~waterLevel~0)| ~waterLevel~0) (= 77 (select (select |#memory_int| 17) 1)) (= 110 (select (select |#memory_int| 22) 1)) (= 9 (select |#length| 14)) (= (select (select |#memory_int| 17) 4) 104) (= (select |#valid| 0) 0) (= 79 (select (select |#memory_int| 26) 0)) (= (select (select |#memory_int| 28) 0) 10) (= (select |#valid| 25) 1) (<= ~head~0.base 0) (= 112 (select (select |#memory_int| 24) 4)) (= (select (select |#memory_int| 23) 3) 0) (= 116 (select (select |#memory_int| 17) 3)) (= (select |#valid| 2) 1) (= (select (select |#memory_int| 20) 0) 41) (= 9 (select |#length| 11)) (= 44 (select (select |#memory_int| 24) 0)) (= (select (select |#memory_int| 26) 1) 102) (= (select (select |#memory_int| 1) 0) 48) (= 67 (select (select |#memory_int| 18) 0)) (= (select |#valid| 23) 1) (= 4 (select |#length| 23)) (= (select (select |#memory_int| 23) 0) 79) (= (select (select |#memory_int| 27) 1) 32) (= 101 (select (select |#memory_int| 17) 2)) (= (select |#valid| 19) 1) (= (select (select |#memory_int| 19) 1) 75) (= (select (select |#memory_int| 20) 1) 0) (<= 0 |#NULL.offset|) (= 44 (select (select |#memory_int| 17) 0)) (= (select |#valid| 16) 1) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (= (select |#valid| 6) 1) (= (select (select |#memory_int| 1) 1) 0) (= (select |#length| 17) 7) (= (select |#valid| 17) 1) (= (select |#valid| 10) 1) (= (select |#valid| 8) 1) (= (select (select |#memory_int| 17) 5) 58) (= (select |#valid| 13) 1) (< 0 |#StackHeapBarrier|) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|) (= (select (select |#memory_int| 25) 0) 79))' at error location [2022-11-16 16:08:41,736 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 16:08:41,737 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 16:08:41,737 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 8, 10] total 19 [2022-11-16 16:08:41,737 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [378824624] [2022-11-16 16:08:41,737 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 16:08:41,738 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2022-11-16 16:08:41,738 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:08:41,738 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2022-11-16 16:08:41,739 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=239, Invalid=1567, Unknown=0, NotChecked=0, Total=1806 [2022-11-16 16:08:41,739 INFO L87 Difference]: Start difference. First operand 269 states and 339 transitions. Second operand has 19 states, 16 states have (on average 2.9375) internal successors, (47), 16 states have internal predecessors, (47), 4 states have call successors, (10), 3 states have call predecessors, (10), 9 states have return successors, (11), 6 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-16 16:08:44,232 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:08:44,233 INFO L93 Difference]: Finished difference Result 1356 states and 1842 transitions. [2022-11-16 16:08:44,233 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 57 states. [2022-11-16 16:08:44,233 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 16 states have (on average 2.9375) internal successors, (47), 16 states have internal predecessors, (47), 4 states have call successors, (10), 3 states have call predecessors, (10), 9 states have return successors, (11), 6 states have call predecessors, (11), 4 states have call successors, (11) Word has length 35 [2022-11-16 16:08:44,234 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:08:44,241 INFO L225 Difference]: With dead ends: 1356 [2022-11-16 16:08:44,241 INFO L226 Difference]: Without dead ends: 1196 [2022-11-16 16:08:44,245 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 161 GetRequests, 71 SyntacticMatches, 5 SemanticMatches, 85 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2810 ImplicationChecksByTransitivity, 49.3s TimeCoverageRelationStatistics Valid=802, Invalid=6680, Unknown=0, NotChecked=0, Total=7482 [2022-11-16 16:08:44,246 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 746 mSDsluCounter, 588 mSDsCounter, 0 mSdLazyCounter, 1068 mSolverCounterSat, 393 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 754 SdHoareTripleChecker+Valid, 714 SdHoareTripleChecker+Invalid, 1461 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 393 IncrementalHoareTripleChecker+Valid, 1068 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.1s IncrementalHoareTripleChecker+Time [2022-11-16 16:08:44,246 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [754 Valid, 714 Invalid, 1461 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [393 Valid, 1068 Invalid, 0 Unknown, 0 Unchecked, 1.1s Time] [2022-11-16 16:08:44,248 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1196 states. [2022-11-16 16:08:44,373 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1196 to 968. [2022-11-16 16:08:44,376 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 968 states, 683 states have (on average 1.2606149341142021) internal successors, (861), 722 states have internal predecessors, (861), 151 states have call successors, (151), 118 states have call predecessors, (151), 133 states have return successors, (237), 150 states have call predecessors, (237), 151 states have call successors, (237) [2022-11-16 16:08:44,382 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 968 states to 968 states and 1249 transitions. [2022-11-16 16:08:44,382 INFO L78 Accepts]: Start accepts. Automaton has 968 states and 1249 transitions. Word has length 35 [2022-11-16 16:08:44,383 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:08:44,383 INFO L495 AbstractCegarLoop]: Abstraction has 968 states and 1249 transitions. [2022-11-16 16:08:44,383 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 16 states have (on average 2.9375) internal successors, (47), 16 states have internal predecessors, (47), 4 states have call successors, (10), 3 states have call predecessors, (10), 9 states have return successors, (11), 6 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-16 16:08:44,383 INFO L276 IsEmpty]: Start isEmpty. Operand 968 states and 1249 transitions. [2022-11-16 16:08:44,384 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-16 16:08:44,385 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:08:44,385 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:08:44,400 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-16 16:08:44,600 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable6 [2022-11-16 16:08:44,600 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:08:44,601 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:08:44,601 INFO L85 PathProgramCache]: Analyzing trace with hash 1154155862, now seen corresponding path program 1 times [2022-11-16 16:08:44,601 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:08:44,601 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1318623914] [2022-11-16 16:08:44,601 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:08:44,601 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:08:44,615 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:08:44,741 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-16 16:08:44,742 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:08:44,742 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1318623914] [2022-11-16 16:08:44,742 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1318623914] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:08:44,742 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-16 16:08:44,742 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-11-16 16:08:44,742 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1458034844] [2022-11-16 16:08:44,743 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:08:44,748 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-16 16:08:44,748 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:08:44,748 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-16 16:08:44,749 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=56, Unknown=0, NotChecked=0, Total=72 [2022-11-16 16:08:44,749 INFO L87 Difference]: Start difference. First operand 968 states and 1249 transitions. Second operand has 9 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 3 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) [2022-11-16 16:08:45,319 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:08:45,320 INFO L93 Difference]: Finished difference Result 2322 states and 3086 transitions. [2022-11-16 16:08:45,320 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-11-16 16:08:45,320 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 3 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) Word has length 38 [2022-11-16 16:08:45,321 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:08:45,331 INFO L225 Difference]: With dead ends: 2322 [2022-11-16 16:08:45,331 INFO L226 Difference]: Without dead ends: 1611 [2022-11-16 16:08:45,334 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 22 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=56, Invalid=184, Unknown=0, NotChecked=0, Total=240 [2022-11-16 16:08:45,337 INFO L413 NwaCegarLoop]: 19 mSDtfsCounter, 137 mSDsluCounter, 74 mSDsCounter, 0 mSdLazyCounter, 447 mSolverCounterSat, 73 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 140 SdHoareTripleChecker+Valid, 93 SdHoareTripleChecker+Invalid, 520 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 73 IncrementalHoareTripleChecker+Valid, 447 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 16:08:45,337 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [140 Valid, 93 Invalid, 520 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [73 Valid, 447 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 16:08:45,340 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1611 states. [2022-11-16 16:08:45,530 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1611 to 1611. [2022-11-16 16:08:45,533 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1611 states, 1119 states have (on average 1.2144772117962466) internal successors, (1359), 1184 states have internal predecessors, (1359), 261 states have call successors, (261), 203 states have call predecessors, (261), 230 states have return successors, (423), 261 states have call predecessors, (423), 261 states have call successors, (423) [2022-11-16 16:08:45,542 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1611 states to 1611 states and 2043 transitions. [2022-11-16 16:08:45,543 INFO L78 Accepts]: Start accepts. Automaton has 1611 states and 2043 transitions. Word has length 38 [2022-11-16 16:08:45,543 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:08:45,543 INFO L495 AbstractCegarLoop]: Abstraction has 1611 states and 2043 transitions. [2022-11-16 16:08:45,544 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 7 states have (on average 3.857142857142857) internal successors, (27), 7 states have internal predecessors, (27), 3 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) [2022-11-16 16:08:45,544 INFO L276 IsEmpty]: Start isEmpty. Operand 1611 states and 2043 transitions. [2022-11-16 16:08:45,546 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2022-11-16 16:08:45,546 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:08:45,546 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:08:45,547 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-16 16:08:45,547 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:08:45,547 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:08:45,547 INFO L85 PathProgramCache]: Analyzing trace with hash 1564877046, now seen corresponding path program 1 times [2022-11-16 16:08:45,547 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:08:45,548 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1371747687] [2022-11-16 16:08:45,548 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:08:45,548 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:08:45,574 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:08:45,671 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 16 proven. 1 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-16 16:08:45,671 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:08:45,671 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1371747687] [2022-11-16 16:08:45,671 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1371747687] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 16:08:45,672 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2061719257] [2022-11-16 16:08:45,672 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:08:45,672 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:08:45,672 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:08:45,675 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 16:08:45,699 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-16 16:08:45,793 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:08:45,796 INFO L263 TraceCheckSpWp]: Trace formula consists of 420 conjuncts, 24 conjunts are in the unsatisfiable core [2022-11-16 16:08:45,799 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 16:08:46,074 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-16 16:08:46,074 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 16:08:46,074 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2061719257] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:08:46,074 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 16:08:46,075 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [7] total 14 [2022-11-16 16:08:46,075 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1522216419] [2022-11-16 16:08:46,075 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:08:46,075 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-16 16:08:46,076 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:08:46,076 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-16 16:08:46,076 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=29, Invalid=153, Unknown=0, NotChecked=0, Total=182 [2022-11-16 16:08:46,077 INFO L87 Difference]: Start difference. First operand 1611 states and 2043 transitions. Second operand has 9 states, 9 states have (on average 4.444444444444445) internal successors, (40), 9 states have internal predecessors, (40), 5 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-16 16:08:46,782 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:08:46,783 INFO L93 Difference]: Finished difference Result 2558 states and 3265 transitions. [2022-11-16 16:08:46,783 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-16 16:08:46,783 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 4.444444444444445) internal successors, (40), 9 states have internal predecessors, (40), 5 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) Word has length 52 [2022-11-16 16:08:46,784 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:08:46,790 INFO L225 Difference]: With dead ends: 2558 [2022-11-16 16:08:46,794 INFO L226 Difference]: Without dead ends: 1380 [2022-11-16 16:08:46,800 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 66 GetRequests, 47 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 28 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=75, Invalid=345, Unknown=0, NotChecked=0, Total=420 [2022-11-16 16:08:46,802 INFO L413 NwaCegarLoop]: 49 mSDtfsCounter, 128 mSDsluCounter, 172 mSDsCounter, 0 mSdLazyCounter, 362 mSolverCounterSat, 64 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 134 SdHoareTripleChecker+Valid, 221 SdHoareTripleChecker+Invalid, 426 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 64 IncrementalHoareTripleChecker+Valid, 362 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-16 16:08:46,803 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [134 Valid, 221 Invalid, 426 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [64 Valid, 362 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-16 16:08:46,805 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1380 states. [2022-11-16 16:08:46,931 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1380 to 898. [2022-11-16 16:08:46,933 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 898 states, 616 states have (on average 1.1866883116883118) internal successors, (731), 656 states have internal predecessors, (731), 145 states have call successors, (145), 123 states have call predecessors, (145), 136 states have return successors, (191), 148 states have call predecessors, (191), 145 states have call successors, (191) [2022-11-16 16:08:46,937 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 898 states to 898 states and 1067 transitions. [2022-11-16 16:08:46,938 INFO L78 Accepts]: Start accepts. Automaton has 898 states and 1067 transitions. Word has length 52 [2022-11-16 16:08:46,940 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:08:46,940 INFO L495 AbstractCegarLoop]: Abstraction has 898 states and 1067 transitions. [2022-11-16 16:08:46,940 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 4.444444444444445) internal successors, (40), 9 states have internal predecessors, (40), 5 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-16 16:08:46,941 INFO L276 IsEmpty]: Start isEmpty. Operand 898 states and 1067 transitions. [2022-11-16 16:08:46,943 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2022-11-16 16:08:46,943 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:08:46,943 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:08:46,955 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-16 16:08:47,149 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:08:47,149 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:08:47,150 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:08:47,150 INFO L85 PathProgramCache]: Analyzing trace with hash 53155662, now seen corresponding path program 1 times [2022-11-16 16:08:47,150 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:08:47,150 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1168987964] [2022-11-16 16:08:47,150 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:08:47,151 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:08:47,184 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:08:47,307 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 16 proven. 1 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-16 16:08:47,307 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:08:47,308 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1168987964] [2022-11-16 16:08:47,308 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1168987964] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 16:08:47,308 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1648457439] [2022-11-16 16:08:47,308 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:08:47,308 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:08:47,308 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:08:47,309 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 16:08:47,315 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-16 16:08:47,419 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:08:47,422 INFO L263 TraceCheckSpWp]: Trace formula consists of 426 conjuncts, 24 conjunts are in the unsatisfiable core [2022-11-16 16:08:47,424 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 16:08:47,681 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 4 proven. 11 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-16 16:08:47,681 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 16:08:48,074 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 6 proven. 2 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-11-16 16:08:48,075 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1648457439] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 16:08:48,075 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [63593417] [2022-11-16 16:08:48,077 INFO L159 IcfgInterpreter]: Started Sifa with 37 locations of interest [2022-11-16 16:08:48,078 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 16:08:48,078 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 16:08:48,079 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 16:08:48,079 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 16:08:55,486 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 294 for LOIs [2022-11-16 16:08:55,522 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 299 for LOIs [2022-11-16 16:08:57,404 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 299 for LOIs [2022-11-16 16:08:58,954 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 44 for LOIs [2022-11-16 16:08:58,960 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 16:09:24,331 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '19082#(and (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (= ~methaneLevelCritical~0 0) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1|) (= ~head~0.offset 0) (= |timeShift_getWaterLevel_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|) (= 0 |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~11#1|) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (<= 2 |old(~waterLevel~0)|) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~11#1|) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|))' at error location [2022-11-16 16:09:24,331 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 16:09:24,331 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 16:09:24,331 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 8] total 19 [2022-11-16 16:09:24,331 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1748141908] [2022-11-16 16:09:24,331 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 16:09:24,332 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2022-11-16 16:09:24,332 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:09:24,332 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2022-11-16 16:09:24,333 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=241, Invalid=1565, Unknown=0, NotChecked=0, Total=1806 [2022-11-16 16:09:24,333 INFO L87 Difference]: Start difference. First operand 898 states and 1067 transitions. Second operand has 19 states, 17 states have (on average 5.705882352941177) internal successors, (97), 18 states have internal predecessors, (97), 9 states have call successors, (19), 7 states have call predecessors, (19), 7 states have return successors, (16), 10 states have call predecessors, (16), 9 states have call successors, (16) [2022-11-16 16:09:29,813 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:09:29,813 INFO L93 Difference]: Finished difference Result 2645 states and 3288 transitions. [2022-11-16 16:09:29,814 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 103 states. [2022-11-16 16:09:29,814 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 17 states have (on average 5.705882352941177) internal successors, (97), 18 states have internal predecessors, (97), 9 states have call successors, (19), 7 states have call predecessors, (19), 7 states have return successors, (16), 10 states have call predecessors, (16), 9 states have call successors, (16) Word has length 55 [2022-11-16 16:09:29,814 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:09:29,823 INFO L225 Difference]: With dead ends: 2645 [2022-11-16 16:09:29,823 INFO L226 Difference]: Without dead ends: 1749 [2022-11-16 16:09:29,831 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 296 GetRequests, 148 SyntacticMatches, 6 SemanticMatches, 142 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7985 ImplicationChecksByTransitivity, 28.7s TimeCoverageRelationStatistics Valid=1942, Invalid=18650, Unknown=0, NotChecked=0, Total=20592 [2022-11-16 16:09:29,832 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 1290 mSDsluCounter, 785 mSDsCounter, 0 mSdLazyCounter, 2747 mSolverCounterSat, 859 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1290 SdHoareTripleChecker+Valid, 911 SdHoareTripleChecker+Invalid, 3606 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 859 IncrementalHoareTripleChecker+Valid, 2747 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.0s IncrementalHoareTripleChecker+Time [2022-11-16 16:09:29,832 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1290 Valid, 911 Invalid, 3606 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [859 Valid, 2747 Invalid, 0 Unknown, 0 Unchecked, 2.0s Time] [2022-11-16 16:09:29,834 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1749 states. [2022-11-16 16:09:30,066 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1749 to 1581. [2022-11-16 16:09:30,068 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1581 states, 1080 states have (on average 1.1472222222222221) internal successors, (1239), 1150 states have internal predecessors, (1239), 258 states have call successors, (258), 230 states have call predecessors, (258), 242 states have return successors, (346), 254 states have call predecessors, (346), 258 states have call successors, (346) [2022-11-16 16:09:30,074 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1581 states to 1581 states and 1843 transitions. [2022-11-16 16:09:30,075 INFO L78 Accepts]: Start accepts. Automaton has 1581 states and 1843 transitions. Word has length 55 [2022-11-16 16:09:30,075 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:09:30,075 INFO L495 AbstractCegarLoop]: Abstraction has 1581 states and 1843 transitions. [2022-11-16 16:09:30,076 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 17 states have (on average 5.705882352941177) internal successors, (97), 18 states have internal predecessors, (97), 9 states have call successors, (19), 7 states have call predecessors, (19), 7 states have return successors, (16), 10 states have call predecessors, (16), 9 states have call successors, (16) [2022-11-16 16:09:30,076 INFO L276 IsEmpty]: Start isEmpty. Operand 1581 states and 1843 transitions. [2022-11-16 16:09:30,078 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2022-11-16 16:09:30,078 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:09:30,079 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:09:30,084 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-16 16:09:30,284 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:09:30,284 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:09:30,284 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:09:30,285 INFO L85 PathProgramCache]: Analyzing trace with hash -227513800, now seen corresponding path program 1 times [2022-11-16 16:09:30,285 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:09:30,285 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1748172751] [2022-11-16 16:09:30,285 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:09:30,285 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:09:30,303 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:09:31,112 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 5 proven. 14 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-16 16:09:31,113 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:09:31,113 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1748172751] [2022-11-16 16:09:31,113 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1748172751] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 16:09:31,113 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [538681967] [2022-11-16 16:09:31,113 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:09:31,113 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:09:31,113 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:09:31,115 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 16:09:31,139 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-16 16:09:31,232 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:09:31,234 INFO L263 TraceCheckSpWp]: Trace formula consists of 450 conjuncts, 23 conjunts are in the unsatisfiable core [2022-11-16 16:09:31,236 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 16:09:31,352 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 12 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-11-16 16:09:31,352 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-16 16:09:31,352 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [538681967] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-16 16:09:31,352 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-16 16:09:31,352 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [18] total 21 [2022-11-16 16:09:31,353 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1458795133] [2022-11-16 16:09:31,353 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-16 16:09:31,354 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-16 16:09:31,354 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:09:31,355 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-16 16:09:31,355 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=60, Invalid=360, Unknown=0, NotChecked=0, Total=420 [2022-11-16 16:09:31,356 INFO L87 Difference]: Start difference. First operand 1581 states and 1843 transitions. Second operand has 6 states, 6 states have (on average 6.166666666666667) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 16:09:31,765 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:09:31,766 INFO L93 Difference]: Finished difference Result 2856 states and 3348 transitions. [2022-11-16 16:09:31,766 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-16 16:09:31,766 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.166666666666667) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 69 [2022-11-16 16:09:31,768 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:09:31,776 INFO L225 Difference]: With dead ends: 2856 [2022-11-16 16:09:31,776 INFO L226 Difference]: Without dead ends: 1588 [2022-11-16 16:09:31,780 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 96 GetRequests, 73 SyntacticMatches, 1 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 142 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=75, Invalid=477, Unknown=0, NotChecked=0, Total=552 [2022-11-16 16:09:31,781 INFO L413 NwaCegarLoop]: 45 mSDtfsCounter, 48 mSDsluCounter, 139 mSDsCounter, 0 mSdLazyCounter, 109 mSolverCounterSat, 12 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 52 SdHoareTripleChecker+Valid, 184 SdHoareTripleChecker+Invalid, 121 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 12 IncrementalHoareTripleChecker+Valid, 109 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-16 16:09:31,781 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [52 Valid, 184 Invalid, 121 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [12 Valid, 109 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-16 16:09:31,783 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1588 states. [2022-11-16 16:09:32,017 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1588 to 1576. [2022-11-16 16:09:32,020 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1576 states, 1075 states have (on average 1.1386046511627907) internal successors, (1224), 1145 states have internal predecessors, (1224), 258 states have call successors, (258), 230 states have call predecessors, (258), 242 states have return successors, (346), 254 states have call predecessors, (346), 258 states have call successors, (346) [2022-11-16 16:09:32,032 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1576 states to 1576 states and 1828 transitions. [2022-11-16 16:09:32,032 INFO L78 Accepts]: Start accepts. Automaton has 1576 states and 1828 transitions. Word has length 69 [2022-11-16 16:09:32,034 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:09:32,035 INFO L495 AbstractCegarLoop]: Abstraction has 1576 states and 1828 transitions. [2022-11-16 16:09:32,035 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.166666666666667) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-11-16 16:09:32,035 INFO L276 IsEmpty]: Start isEmpty. Operand 1576 states and 1828 transitions. [2022-11-16 16:09:32,037 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2022-11-16 16:09:32,037 INFO L187 NwaCegarLoop]: Found error trace [2022-11-16 16:09:32,037 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:09:32,048 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-11-16 16:09:32,243 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-16 16:09:32,243 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-16 16:09:32,243 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-16 16:09:32,243 INFO L85 PathProgramCache]: Analyzing trace with hash -958762916, now seen corresponding path program 2 times [2022-11-16 16:09:32,243 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-16 16:09:32,243 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [422863328] [2022-11-16 16:09:32,244 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-16 16:09:32,244 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-16 16:09:32,262 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-16 16:09:32,587 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 19 proven. 4 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-16 16:09:32,587 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-16 16:09:32,587 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [422863328] [2022-11-16 16:09:32,587 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [422863328] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-16 16:09:32,587 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1715607503] [2022-11-16 16:09:32,588 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST2 [2022-11-16 16:09:32,588 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-16 16:09:32,588 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 [2022-11-16 16:09:32,589 INFO L229 MonitoredProcess]: Starting monitored process 6 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-16 16:09:32,611 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Waiting until timeout for monitored process [2022-11-16 16:09:32,703 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST2 issued 2 check-sat command(s) [2022-11-16 16:09:32,703 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-11-16 16:09:32,706 INFO L263 TraceCheckSpWp]: Trace formula consists of 450 conjuncts, 31 conjunts are in the unsatisfiable core [2022-11-16 16:09:32,708 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-16 16:09:32,883 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 25 proven. 5 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-16 16:09:32,883 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-16 16:09:33,329 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 19 proven. 4 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2022-11-16 16:09:33,330 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1715607503] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-16 16:09:33,330 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [628589471] [2022-11-16 16:09:33,338 INFO L159 IcfgInterpreter]: Started Sifa with 42 locations of interest [2022-11-16 16:09:33,338 INFO L166 IcfgInterpreter]: Building call graph [2022-11-16 16:09:33,338 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-16 16:09:33,339 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-16 16:09:33,339 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-16 16:09:39,068 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 43 for LOIs [2022-11-16 16:09:39,078 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 51 for LOIs [2022-11-16 16:09:39,323 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 50 for LOIs [2022-11-16 16:09:39,768 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 40 for LOIs [2022-11-16 16:09:39,774 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 41 for LOIs [2022-11-16 16:09:39,782 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 51 for LOIs [2022-11-16 16:09:39,792 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-16 16:09:47,187 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '33614#(and (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1|) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (= |timeShift_getWaterLevel_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|) (<= |#NULL.offset| 0) (= 0 |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~11#1|) (= |old(~pumpRunning~0)| 0) (= |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1| 0) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~11#1|) (<= 0 ~head~0.base) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification3_spec__1_~tmp___1~0#1|) (<= 0 |#StackHeapBarrier|) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|))' at error location [2022-11-16 16:09:47,187 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-16 16:09:47,188 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-16 16:09:47,188 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 14, 13] total 25 [2022-11-16 16:09:47,188 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1575234289] [2022-11-16 16:09:47,188 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-16 16:09:47,189 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 25 states [2022-11-16 16:09:47,189 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-16 16:09:47,189 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 25 interpolants. [2022-11-16 16:09:47,190 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=252, Invalid=2940, Unknown=0, NotChecked=0, Total=3192 [2022-11-16 16:09:47,190 INFO L87 Difference]: Start difference. First operand 1576 states and 1828 transitions. Second operand has 25 states, 20 states have (on average 3.35) internal successors, (67), 18 states have internal predecessors, (67), 5 states have call successors, (17), 6 states have call predecessors, (17), 11 states have return successors, (19), 10 states have call predecessors, (19), 5 states have call successors, (19) [2022-11-16 16:09:48,962 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-16 16:09:48,962 INFO L93 Difference]: Finished difference Result 2679 states and 3212 transitions. [2022-11-16 16:09:48,963 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 29 states. [2022-11-16 16:09:48,963 INFO L78 Accepts]: Start accepts. Automaton has has 25 states, 20 states have (on average 3.35) internal successors, (67), 18 states have internal predecessors, (67), 5 states have call successors, (17), 6 states have call predecessors, (17), 11 states have return successors, (19), 10 states have call predecessors, (19), 5 states have call successors, (19) Word has length 69 [2022-11-16 16:09:48,963 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-16 16:09:48,964 INFO L225 Difference]: With dead ends: 2679 [2022-11-16 16:09:48,964 INFO L226 Difference]: Without dead ends: 0 [2022-11-16 16:09:48,972 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 248 GetRequests, 166 SyntacticMatches, 3 SemanticMatches, 79 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1912 ImplicationChecksByTransitivity, 8.3s TimeCoverageRelationStatistics Valid=564, Invalid=5916, Unknown=0, NotChecked=0, Total=6480 [2022-11-16 16:09:48,973 INFO L413 NwaCegarLoop]: 36 mSDtfsCounter, 422 mSDsluCounter, 276 mSDsCounter, 0 mSdLazyCounter, 1473 mSolverCounterSat, 307 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 425 SdHoareTripleChecker+Valid, 312 SdHoareTripleChecker+Invalid, 1780 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 307 IncrementalHoareTripleChecker+Valid, 1473 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2022-11-16 16:09:48,974 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [425 Valid, 312 Invalid, 1780 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [307 Valid, 1473 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2022-11-16 16:09:48,974 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-16 16:09:48,974 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-16 16:09:48,974 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-16 16:09:48,975 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-16 16:09:48,975 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 69 [2022-11-16 16:09:48,975 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-16 16:09:48,975 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-16 16:09:48,976 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 25 states, 20 states have (on average 3.35) internal successors, (67), 18 states have internal predecessors, (67), 5 states have call successors, (17), 6 states have call predecessors, (17), 11 states have return successors, (19), 10 states have call predecessors, (19), 5 states have call successors, (19) [2022-11-16 16:09:48,976 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-16 16:09:48,976 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-16 16:09:48,979 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-16 16:09:48,989 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Forceful destruction successful, exit code 0 [2022-11-16 16:09:49,189 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 6 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-16 16:09:49,191 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-16 16:10:16,048 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 805 811) no Hoare annotation was computed. [2022-11-16 16:10:16,048 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 805 811) the Hoare annotation is: true [2022-11-16 16:10:16,048 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 596 607) the Hoare annotation is: (let ((.cse5 (not (< ~waterLevel~0 2))) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse3 (not (= |old(~methaneLevelCritical~0)| 1))) (.cse4 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= 2 ~waterLevel~0))) (.cse6 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse0 .cse5 .cse6) (or .cse0 .cse5 .cse2 .cse3) (or .cse4 .cse0 .cse1 .cse6))) [2022-11-16 16:10:16,049 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 596 607) no Hoare annotation was computed. [2022-11-16 16:10:16,049 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 608 616) the Hoare annotation is: true [2022-11-16 16:10:16,049 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 608 616) no Hoare annotation was computed. [2022-11-16 16:10:16,050 INFO L895 garLoopResultBuilder]: At program point L853(line 853) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (< |old(~waterLevel~0)| 2))) (.cse8 (let ((.cse10 (= ~pumpRunning~0 0))) (let ((.cse12 (not .cse10))) (and (let ((.cse11 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse10 .cse11) (and .cse12 (let ((.cse13 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse13) .cse11) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse13)))))) (or (not (<= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|)) .cse12) (< ~waterLevel~0 2))))) (.cse3 (not (< |old(~waterLevel~0)| 3))) (.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse7 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse1 .cse5 .cse2 .cse6 .cse7) (or .cse1 .cse5 .cse6 .cse4 .cse7) (or .cse1 .cse2 .cse8 .cse3) (or .cse1 .cse8 .cse4 .cse3) (or .cse1 .cse6 .cse4 .cse9 .cse7) (or .cse1 .cse2 .cse6 .cse9 .cse7))) [2022-11-16 16:10:16,050 INFO L895 garLoopResultBuilder]: At program point L858(line 858) the Hoare annotation is: (let ((.cse3 (not (= |old(~waterLevel~0)| 2))) (.cse0 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse6 (not (< |old(~waterLevel~0)| 2))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse5) (or .cse1 .cse6 .cse7 .cse2) (or .cse1 .cse7 .cse2 .cse3) (or .cse0 .cse1 .cse6 .cse2) (or .cse1 .cse4 .cse7 .cse5))) [2022-11-16 16:10:16,051 INFO L895 garLoopResultBuilder]: At program point L858-1(lines 839 863) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (not (< |old(~waterLevel~0)| 2))) (.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse8 (and .cse4 .cse14)) (.cse9 (not (= ~methaneLevelCritical~0 1))) (.cse11 (not (< |old(~waterLevel~0)| 3))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse12 (= ~waterLevel~0 1)) (.cse6 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2 .cse3 (and .cse4 .cse5) .cse6) (or .cse7 .cse8 .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse9 .cse5) (let ((.cse10 (< ~waterLevel~0 2))) (or .cse0 (and .cse4 .cse5 .cse10) .cse3 .cse9 .cse11 (and .cse10 .cse6))) (or (and .cse12 .cse6) .cse4 .cse0 .cse2 .cse3 .cse13) (or .cse0 .cse9 .cse13 .cse14 .cse12) (or .cse0 .cse1 .cse2 .cse5) (or .cse7 .cse8 .cse0 (<= 2 ~waterLevel~0) .cse9 .cse11) (or .cse7 .cse0 .cse2 .cse13 .cse14) (or .cse0 .cse2 .cse13 .cse12 (and .cse14 .cse6))))) [2022-11-16 16:10:16,051 INFO L899 garLoopResultBuilder]: For program point L792-1(lines 792 798) no Hoare annotation was computed. [2022-11-16 16:10:16,051 INFO L899 garLoopResultBuilder]: For program point L693(lines 693 699) no Hoare annotation was computed. [2022-11-16 16:10:16,051 INFO L895 garLoopResultBuilder]: At program point L689(lines 689 702) the Hoare annotation is: (let ((.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (<= 2 ~waterLevel~0)) (.cse1 (= ~pumpRunning~0 0)) (.cse6 (not (< |old(~waterLevel~0)| 3))) (.cse11 (< ~waterLevel~0 2)) (.cse12 (= ~pumpRunning~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse7 (not (= ~methaneLevelCritical~0 1))) (.cse8 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4 .cse5 .cse6) (or .cse3 (not (< |old(~waterLevel~0)| 2)) .cse7) (or .cse3 .cse5 .cse8 .cse2 (= ~waterLevel~0 1)) (let ((.cse9 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1|)) (.cse10 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse9 (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1| 1) .cse10 .cse11) .cse3 (and .cse9 .cse4 .cse10 .cse12) .cse5 .cse6)) (or .cse1 .cse3 .cse5 (not (= |old(~pumpRunning~0)| 1)) .cse6 (and .cse11 .cse12)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 .cse5 (= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1| 1)) (or .cse3 .cse7 .cse8))) [2022-11-16 16:10:16,052 INFO L895 garLoopResultBuilder]: At program point L689-1(lines 674 706) the Hoare annotation is: (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse17 (= ~pumpRunning~0 0)) (.cse16 (= 1 ~systemActive~0))) (let ((.cse3 (and .cse17 .cse16)) (.cse5 (= ~pumpRunning~0 1)) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse6 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1|)) (.cse8 (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1| 1)) (.cse13 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (< |old(~waterLevel~0)| 3))) (.cse10 (not (= |old(~waterLevel~0)| 2))) (.cse9 (= ~waterLevel~0 1)) (.cse14 (and .cse17 .cse16 .cse7)) (.cse15 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not .cse16)) (.cse12 (not (< |old(~waterLevel~0)| 2))) (.cse11 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse0 .cse1 (and .cse6 .cse7 .cse5) (and .cse6 .cse8 .cse9) .cse10) (or .cse0 .cse2 .cse11 .cse3 .cse4 .cse5) (or .cse0 .cse12 .cse11 .cse13) (or (not (<= |old(~waterLevel~0)| 1)) .cse14 .cse15 .cse0 .cse1) (or .cse15 .cse0 .cse11 .cse10 .cse7) (or .cse0 .cse1 .cse2 .cse10 .cse9) (or .cse0 .cse2 .cse11 .cse10 .cse9) (or (and .cse6 .cse8 .cse13) .cse0 .cse12 .cse1) (or .cse15 .cse0 .cse1 .cse10 .cse7) (or .cse0 .cse11 (and (= |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1| 1) (< ~waterLevel~0 3)) .cse4) (or .cse0 (<= 2 ~waterLevel~0) .cse11 .cse10 .cse9) (or .cse14 .cse15 .cse0 .cse12 .cse11)))) [2022-11-16 16:10:16,052 INFO L895 garLoopResultBuilder]: At program point L681(line 681) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse14 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (not (< |old(~waterLevel~0)| 2))) (.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse8 (and .cse4 .cse14)) (.cse9 (not (= ~methaneLevelCritical~0 1))) (.cse11 (not (< |old(~waterLevel~0)| 3))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse12 (= ~waterLevel~0 1)) (.cse6 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2 .cse3 (and .cse4 .cse5) .cse6) (or .cse7 .cse8 .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse9 .cse5) (let ((.cse10 (< ~waterLevel~0 2))) (or .cse0 (and .cse4 .cse5 .cse10) .cse3 .cse9 .cse11 (and .cse10 .cse6))) (or (and .cse12 .cse6) .cse4 .cse0 .cse2 .cse3 .cse13) (or .cse0 .cse9 .cse13 .cse14 .cse12) (or .cse0 .cse1 .cse2 .cse5) (or .cse7 .cse8 .cse0 (<= 2 ~waterLevel~0) .cse9 .cse11) (or .cse7 .cse0 .cse2 .cse13 .cse14) (or .cse0 .cse2 .cse13 .cse12 (and .cse14 .cse6))))) [2022-11-16 16:10:16,053 INFO L899 garLoopResultBuilder]: For program point L681-1(line 681) no Hoare annotation was computed. [2022-11-16 16:10:16,053 INFO L899 garLoopResultBuilder]: For program point L785-1(lines 784 803) no Hoare annotation was computed. [2022-11-16 16:10:16,053 INFO L895 garLoopResultBuilder]: At program point L847(lines 847 855) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (< |old(~waterLevel~0)| 2))) (.cse8 (let ((.cse10 (= ~pumpRunning~0 0))) (let ((.cse12 (not .cse10))) (and (let ((.cse11 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse10 .cse11) (and .cse12 (let ((.cse13 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse13) .cse11) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse13)))))) (or (not (<= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|)) .cse12) (< ~waterLevel~0 2))))) (.cse3 (not (< |old(~waterLevel~0)| 3))) (.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse7 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3) (or .cse1 .cse5 .cse2 .cse6 .cse7) (or .cse1 .cse5 .cse6 .cse4 .cse7) (or .cse1 .cse2 .cse8 .cse3) (or .cse1 .cse8 .cse4 .cse3) (or .cse1 .cse6 .cse4 .cse9 .cse7) (or .cse1 .cse2 .cse6 .cse9 .cse7))) [2022-11-16 16:10:16,053 INFO L895 garLoopResultBuilder]: At program point L843(lines 843 860) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0))) (let ((.cse10 (not .cse1)) (.cse11 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse15 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (< |old(~waterLevel~0)| 3))) (.cse7 (and .cse1 .cse15)) (.cse13 (not (< |old(~waterLevel~0)| 2))) (.cse12 (and .cse10 (let ((.cse14 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse14) .cse15) (and .cse11 .cse14))))) (.cse2 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (not (= ~methaneLevelCritical~0 1))) (.cse9 (not (= |old(~waterLevel~0)| 2))) (.cse6 (= ~pumpRunning~0 1))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (or .cse2 .cse3 .cse4 .cse5 .cse6) (or .cse7 .cse2 .cse8 .cse9 (and .cse10 .cse11)) (or .cse0 .cse1 .cse2 .cse3 .cse9) (or .cse7 .cse2 .cse3 .cse12 .cse5) (or .cse2 .cse13 .cse4 .cse8 .cse6) (or .cse0 .cse1 .cse2 .cse8 .cse5) (or .cse7 .cse2 .cse13 .cse12 .cse8) (or .cse2 .cse4 .cse8 .cse9 .cse6))))) [2022-11-16 16:10:16,054 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 781 804) the Hoare annotation is: (let ((.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (< |old(~waterLevel~0)| 3))) (.cse5 (= ~pumpRunning~0 1)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (not (= ~methaneLevelCritical~0 1))) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse9 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (= ~pumpRunning~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse8 (not (< |old(~waterLevel~0)| 2))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse3 .cse5) (or .cse0 .cse4 .cse6 .cse3 .cse5) (or .cse0 .cse6 .cse7 .cse2) (or .cse0 .cse8 .cse6 .cse2) (or (not (<= |old(~waterLevel~0)| 1)) .cse9 .cse10 .cse0 .cse6) (or .cse9 .cse10 .cse0 .cse1 .cse7) (or .cse9 .cse10 .cse0 .cse6 .cse7) (or .cse9 .cse10 .cse0 .cse8 .cse1))) [2022-11-16 16:10:16,054 INFO L895 garLoopResultBuilder]: At program point L559(line 559) the Hoare annotation is: (let ((.cse1 (not (< |old(~waterLevel~0)| 2))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse0 .cse2 .cse4) (or .cse0 .cse3 .cse4))) [2022-11-16 16:10:16,055 INFO L895 garLoopResultBuilder]: At program point L683(lines 683 703) the Hoare annotation is: (let ((.cse9 (< ~waterLevel~0 2)) (.cse15 (= ~pumpRunning~0 1)) (.cse16 (= 1 ~systemActive~0)) (.cse17 (= ~methaneLevelCritical~0 1)) (.cse8 (= ~pumpRunning~0 0)) (.cse18 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and .cse8 .cse18)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse12 (and (= 2 ~waterLevel~0) .cse16 .cse17 .cse18)) (.cse6 (not .cse17)) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse3 (<= 2 ~waterLevel~0)) (.cse14 (= ~waterLevel~0 1)) (.cse2 (not .cse16)) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse10 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse5 (not (< |old(~waterLevel~0)| 3))) (.cse11 (and .cse9 .cse15))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse6) (or (and (= |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1| 1) .cse7) .cse2 .cse6 .cse5) (or .cse2 (and .cse8 .cse7 .cse9) .cse10 .cse6 .cse5 .cse11) (or .cse12 .cse2 .cse6 .cse13 .cse14) (or .cse0 .cse12 .cse2 .cse6 .cse13) (or .cse2 .cse4 .cse13 (and .cse3 .cse15) .cse14) (or (and (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~4#1|) .cse7) .cse2 .cse4 .cse5) (or .cse2 .cse4 .cse10 (and .cse8 .cse7) .cse5 .cse11)))) [2022-11-16 16:10:16,055 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 781 804) no Hoare annotation was computed. [2022-11-16 16:10:16,055 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 559) no Hoare annotation was computed. [2022-11-16 16:10:16,055 INFO L902 garLoopResultBuilder]: At program point L66-1(lines 66 70) the Hoare annotation is: true [2022-11-16 16:10:16,055 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 52 81) no Hoare annotation was computed. [2022-11-16 16:10:16,055 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 52 81) the Hoare annotation is: true [2022-11-16 16:10:16,056 INFO L902 garLoopResultBuilder]: At program point L62-2(lines 62 76) the Hoare annotation is: true [2022-11-16 16:10:16,056 INFO L902 garLoopResultBuilder]: At program point L58(line 58) the Hoare annotation is: true [2022-11-16 16:10:16,056 INFO L899 garLoopResultBuilder]: For program point L58-1(line 58) no Hoare annotation was computed. [2022-11-16 16:10:16,056 INFO L902 garLoopResultBuilder]: At program point L77(lines 52 81) the Hoare annotation is: true [2022-11-16 16:10:16,056 INFO L899 garLoopResultBuilder]: For program point L73(line 73) no Hoare annotation was computed. [2022-11-16 16:10:16,056 INFO L899 garLoopResultBuilder]: For program point L66(lines 66 70) no Hoare annotation was computed. [2022-11-16 16:10:16,056 INFO L899 garLoopResultBuilder]: For program point L729(lines 729 735) no Hoare annotation was computed. [2022-11-16 16:10:16,056 INFO L899 garLoopResultBuilder]: For program point L729-1(lines 729 735) no Hoare annotation was computed. [2022-11-16 16:10:16,056 INFO L895 garLoopResultBuilder]: At program point L767(lines 718 768) the Hoare annotation is: false [2022-11-16 16:10:16,056 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-16 16:10:16,057 INFO L895 garLoopResultBuilder]: At program point L140(lines 140 147) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-16 16:10:16,057 INFO L902 garLoopResultBuilder]: At program point L140-2(lines 140 147) the Hoare annotation is: true [2022-11-16 16:10:16,057 INFO L899 garLoopResultBuilder]: For program point L739(lines 739 745) no Hoare annotation was computed. [2022-11-16 16:10:16,057 INFO L895 garLoopResultBuilder]: At program point L739-1(lines 739 745) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (< ~waterLevel~0 3))) (or (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse1 (= ~methaneLevelCritical~0 1) .cse2 .cse3))) [2022-11-16 16:10:16,057 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-16 16:10:16,058 INFO L895 garLoopResultBuilder]: At program point L764(lines 719 766) the Hoare annotation is: (let ((.cse0 (= ~methaneLevelCritical~0 0)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and .cse0 .cse1 .cse2 .cse3 (< ~waterLevel~0 2)) (and .cse1 .cse2 (= ~methaneLevelCritical~0 1) .cse3 (< ~waterLevel~0 3)))) [2022-11-16 16:10:16,058 INFO L895 garLoopResultBuilder]: At program point L731(line 731) the Hoare annotation is: (let ((.cse0 (= ~methaneLevelCritical~0 0)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 (< ~waterLevel~0 2)) (and .cse1 .cse2 (= ~methaneLevelCritical~0 1) .cse3 (< ~waterLevel~0 3)) (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3))) [2022-11-16 16:10:16,058 INFO L895 garLoopResultBuilder]: At program point L757-2(lines 749 762) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (< ~waterLevel~0 3))) (or (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse1 (= ~methaneLevelCritical~0 1) .cse2 .cse3))) [2022-11-16 16:10:16,058 INFO L899 garLoopResultBuilder]: For program point L720(lines 719 766) no Hoare annotation was computed. [2022-11-16 16:10:16,058 INFO L895 garLoopResultBuilder]: At program point L741(line 741) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (< ~waterLevel~0 3))) (or (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse1 (= ~methaneLevelCritical~0 1) .cse2 .cse3))) [2022-11-16 16:10:16,058 INFO L902 garLoopResultBuilder]: At program point L770(lines 709 774) the Hoare annotation is: true [2022-11-16 16:10:16,059 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 813 837) the Hoare annotation is: (let ((.cse6 (not (< ~waterLevel~0 2))) (.cse12 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~pumpRunning~0 0))) (let ((.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (= ~pumpRunning~0 1)) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse10 (not (= ~waterLevel~0 1))) (.cse11 (not .cse1)) (.cse8 (and .cse6 .cse12)) (.cse0 (not .cse12)) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= 2 ~waterLevel~0))) (.cse5 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 .cse2 .cse5 (not (<= ~waterLevel~0 1))) (or .cse2 .cse6 .cse4 .cse7 .cse8 .cse9) (or .cse0 .cse1 .cse2 .cse4 .cse8) (or .cse2 .cse6 .cse7 .cse8 .cse5 .cse9) (or .cse10 .cse11 .cse2 .cse12 .cse4 .cse8) (or .cse10 .cse11 .cse2 .cse12 .cse8 .cse5) (or .cse0 .cse1 .cse2 .cse3 .cse5)))) [2022-11-16 16:10:16,059 INFO L895 garLoopResultBuilder]: At program point L832(line 832) the Hoare annotation is: (let ((.cse8 (not (< ~waterLevel~0 2))) (.cse13 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not (= ~waterLevel~0 1))) (.cse7 (not (<= 2 |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1|))) (.cse1 (not (= ~pumpRunning~0 0))) (.cse10 (not (<= ~waterLevel~0 1))) (.cse3 (and .cse8 .cse13)) (.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse5 (not .cse13)) (.cse6 (not (= 2 ~waterLevel~0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse9 (not (= ~methaneLevelCritical~0 0))) (.cse11 (not (= |old(~pumpRunning~0)| 1))) (.cse12 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse2 .cse6 .cse4) (or .cse7 .cse1 .cse2 .cse8 .cse9 .cse3) (or .cse0 .cse1 .cse2 .cse9 .cse3) (or .cse5 .cse2 .cse4 .cse10) (or .cse7 .cse1 .cse2 .cse8 .cse3 .cse4) (or .cse5 .cse2 .cse9 .cse10) (or .cse2 .cse8 .cse11 .cse3 .cse4 .cse12) (or .cse5 .cse2 .cse6 .cse9) (or .cse2 .cse8 .cse9 .cse11 .cse12)))) [2022-11-16 16:10:16,059 INFO L899 garLoopResultBuilder]: For program point L832-1(lines 813 837) no Hoare annotation was computed. [2022-11-16 16:10:16,059 INFO L895 garLoopResultBuilder]: At program point L903(line 903) the Hoare annotation is: (let ((.cse1 (not (< ~waterLevel~0 2))) (.cse3 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse5 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 1))) (.cse6 (not (< ~waterLevel~0 3)))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse3) (or .cse4 .cse0 .cse3 .cse5 .cse6) (or .cse4 .cse0 .cse2 .cse5 .cse6))) [2022-11-16 16:10:16,059 INFO L895 garLoopResultBuilder]: At program point L903-1(line 903) the Hoare annotation is: (let ((.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (< ~waterLevel~0 2))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 1))) (.cse4 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#t~ret44#1| ~methaneLevelCritical~0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse0 .cse2 .cse4 (not (< ~waterLevel~0 3))) (or .cse0 .cse1 .cse5) (or .cse3 .cse0 (not (= 2 ~waterLevel~0)) .cse5 .cse4))) [2022-11-16 16:10:16,060 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 813 837) no Hoare annotation was computed. [2022-11-16 16:10:16,060 INFO L895 garLoopResultBuilder]: At program point L827(line 827) the Hoare annotation is: (let ((.cse4 (not (< ~waterLevel~0 2))) (.cse2 (= |old(~pumpRunning~0)| 0)) (.cse11 (= ~pumpRunning~0 0)) (.cse12 (<= ~waterLevel~0 1)) (.cse14 (= 1 ~systemActive~0)) (.cse15 (= ~methaneLevelCritical~0 1)) (.cse13 (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0))) (let ((.cse0 (not (= ~waterLevel~0 1))) (.cse9 (and .cse11 .cse12 .cse14 .cse15 .cse13)) (.cse7 (and .cse4 .cse2)) (.cse6 (not .cse15)) (.cse8 (not .cse2)) (.cse10 (not (< ~waterLevel~0 3))) (.cse1 (not .cse14)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= |old(~pumpRunning~0)| 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse1 .cse4 .cse5 .cse6) (or .cse0 .cse1 .cse2 .cse7 .cse6) (or .cse8 .cse1 .cse9 .cse6 .cse10) (or .cse1 .cse4 .cse9 .cse7 .cse6) (or .cse1 .cse3 (and .cse11 .cse12 .cse13) (and .cse8 (< 0 ~waterLevel~0)) .cse10) (or .cse1 .cse4 .cse3 .cse5)))) [2022-11-16 16:10:16,060 INFO L899 garLoopResultBuilder]: For program point L821(lines 821 829) no Hoare annotation was computed. [2022-11-16 16:10:16,060 INFO L895 garLoopResultBuilder]: At program point L817(lines 817 834) the Hoare annotation is: (let ((.cse6 (not (< ~waterLevel~0 2))) (.cse12 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~pumpRunning~0 0))) (let ((.cse7 (not (= |old(~pumpRunning~0)| 1))) (.cse9 (= ~pumpRunning~0 1)) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse10 (not (= ~waterLevel~0 1))) (.cse11 (not .cse1)) (.cse8 (and .cse6 .cse12)) (.cse0 (not .cse12)) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= 2 ~waterLevel~0))) (.cse5 (not (= ~methaneLevelCritical~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 .cse2 .cse5 (not (<= ~waterLevel~0 1))) (or .cse2 .cse6 .cse4 .cse7 .cse8 .cse9) (or .cse0 .cse1 .cse2 .cse4 .cse8) (or .cse2 .cse6 .cse7 .cse8 .cse5 .cse9) (or .cse10 .cse11 .cse2 .cse12 .cse4 .cse8) (or .cse10 .cse11 .cse2 .cse12 .cse8 .cse5) (or .cse0 .cse1 .cse2 .cse3 .cse5)))) [2022-11-16 16:10:16,060 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 584 595) no Hoare annotation was computed. [2022-11-16 16:10:16,060 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 584 595) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2) (or .cse0 (not (= ~methaneLevelCritical~0 1)) .cse1 .cse2))) [2022-11-16 16:10:16,063 INFO L444 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-16 16:10:16,065 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-16 16:10:16,127 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.11 04:10:16 BoogieIcfgContainer [2022-11-16 16:10:16,127 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-16 16:10:16,128 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-16 16:10:16,128 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-16 16:10:16,128 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-16 16:10:16,129 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.11 04:07:41" (3/4) ... [2022-11-16 16:10:16,131 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-16 16:10:16,150 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-16 16:10:16,150 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-16 16:10:16,150 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-11-16 16:10:16,150 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-16 16:10:16,150 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-16 16:10:16,151 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-16 16:10:16,151 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-16 16:10:16,158 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 82 nodes and edges [2022-11-16 16:10:16,162 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 25 nodes and edges [2022-11-16 16:10:16,163 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 13 nodes and edges [2022-11-16 16:10:16,164 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-16 16:10:16,164 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-11-16 16:10:16,165 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 16:10:16,165 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-16 16:10:16,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) < 3)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || \old(waterLevel) == waterLevel)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) [2022-11-16 16:10:16,194 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1) [2022-11-16 16:10:16,194 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && waterLevel <= \old(waterLevel))) || pumpRunning == 1) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || waterLevel <= \old(waterLevel))) && (((((!(1 == systemActive) || ((pumpRunning == 0 && waterLevel <= \old(waterLevel)) && waterLevel < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && ((((((waterLevel == 1 && pumpRunning == 1) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || waterLevel <= \old(waterLevel))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || waterLevel == 1) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) [2022-11-16 16:10:16,195 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(waterLevel <= 1))) && (((((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (!(waterLevel < 2) && \old(pumpRunning) == 0))) && (((((!(1 == systemActive) || !(waterLevel < 2)) || !(\old(pumpRunning) == 1)) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && (((((!(waterLevel == 1) || !(pumpRunning == 0)) || !(1 == systemActive)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (!(waterLevel < 2) && \old(pumpRunning) == 0))) && (((((!(waterLevel == 1) || !(pumpRunning == 0)) || !(1 == systemActive)) || \old(pumpRunning) == 0) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) [2022-11-16 16:10:16,196 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && ((((tmp == 1 && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || ((pumpRunning == 0 && waterLevel <= \old(waterLevel)) && waterLevel < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && (((((((2 == waterLevel && 1 == systemActive) && methaneLevelCritical == 1) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((!(\old(pumpRunning) == 0) || (((2 == waterLevel && 1 == systemActive) && methaneLevelCritical == 1) && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || (2 <= waterLevel && pumpRunning == 1)) || waterLevel == 1)) && ((((methaneLevelCritical == tmp && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1)) [2022-11-16 16:10:16,196 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && 1 == systemActive)) || !(\old(waterLevel) < 3)) || pumpRunning == 1) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == tmp && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || ((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel == 1)) || !(\old(waterLevel) == 2))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && 1 == systemActive)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || waterLevel <= \old(waterLevel))) && ((((!(\old(waterLevel) <= 1) || ((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && (((((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && (((!(1 == systemActive) || !(methaneLevelCritical == 1)) || (tmp == 1 && waterLevel < 3)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) [2022-11-16 16:10:16,197 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && tmp == 1) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) || !(waterLevel < 3))) && ((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) || ((pumpRunning == 0 && tmp == 1) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) [2022-11-16 16:10:16,197 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && ((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && (((((((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel <= \old(waterLevel)) && waterLevel < 2) || !(1 == systemActive)) || (((methaneLevelCritical == tmp && 2 <= waterLevel) && waterLevel <= \old(waterLevel)) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3))) && (((((pumpRunning == 0 || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || tmp___0 == 1)) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) [2022-11-16 16:10:16,200 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(methaneLevelCritical == 0)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && (!(2 <= tmp___0) || !(pumpRunning == 0))) && waterLevel < 2)) || !(\old(waterLevel) < 3))) && (((!(1 == systemActive) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && (!(2 <= tmp___0) || !(pumpRunning == 0))) && waterLevel < 2)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1) [2022-11-16 16:10:16,200 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) && ((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1))) && ((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) [2022-11-16 16:10:16,248 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/witness.graphml [2022-11-16 16:10:16,248 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-16 16:10:16,249 INFO L158 Benchmark]: Toolchain (without parser) took 156322.68ms. Allocated memory was 90.2MB in the beginning and 843.1MB in the end (delta: 752.9MB). Free memory was 54.2MB in the beginning and 760.8MB in the end (delta: -706.6MB). Peak memory consumption was 47.2MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,249 INFO L158 Benchmark]: CDTParser took 0.28ms. Allocated memory is still 90.2MB. Free memory was 59.8MB in the beginning and 59.8MB in the end (delta: 28.6kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-16 16:10:16,250 INFO L158 Benchmark]: CACSL2BoogieTranslator took 539.82ms. Allocated memory was 90.2MB in the beginning and 115.3MB in the end (delta: 25.2MB). Free memory was 53.9MB in the beginning and 82.3MB in the end (delta: -28.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,250 INFO L158 Benchmark]: Boogie Procedure Inliner took 64.40ms. Allocated memory is still 115.3MB. Free memory was 82.3MB in the beginning and 79.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,251 INFO L158 Benchmark]: Boogie Preprocessor took 31.98ms. Allocated memory is still 115.3MB. Free memory was 79.8MB in the beginning and 78.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,251 INFO L158 Benchmark]: RCFGBuilder took 805.93ms. Allocated memory is still 115.3MB. Free memory was 78.1MB in the beginning and 43.6MB in the end (delta: 34.5MB). Peak memory consumption was 35.7MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,252 INFO L158 Benchmark]: TraceAbstraction took 154753.16ms. Allocated memory was 115.3MB in the beginning and 843.1MB in the end (delta: 727.7MB). Free memory was 43.0MB in the beginning and 766.1MB in the end (delta: -723.1MB). Peak memory consumption was 479.8MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,252 INFO L158 Benchmark]: Witness Printer took 120.63ms. Allocated memory is still 843.1MB. Free memory was 766.1MB in the beginning and 760.8MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-16 16:10:16,254 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.28ms. Allocated memory is still 90.2MB. Free memory was 59.8MB in the beginning and 59.8MB in the end (delta: 28.6kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 539.82ms. Allocated memory was 90.2MB in the beginning and 115.3MB in the end (delta: 25.2MB). Free memory was 53.9MB in the beginning and 82.3MB in the end (delta: -28.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 64.40ms. Allocated memory is still 115.3MB. Free memory was 82.3MB in the beginning and 79.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 31.98ms. Allocated memory is still 115.3MB. Free memory was 79.8MB in the beginning and 78.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 805.93ms. Allocated memory is still 115.3MB. Free memory was 78.1MB in the beginning and 43.6MB in the end (delta: 34.5MB). Peak memory consumption was 35.7MB. Max. memory is 16.1GB. * TraceAbstraction took 154753.16ms. Allocated memory was 115.3MB in the beginning and 843.1MB in the end (delta: 727.7MB). Free memory was 43.0MB in the beginning and 766.1MB in the end (delta: -723.1MB). Peak memory consumption was 479.8MB. Max. memory is 16.1GB. * Witness Printer took 120.63ms. Allocated memory is still 843.1MB. Free memory was 766.1MB in the beginning and 760.8MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 559]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 58 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 154.6s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 12.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 26.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3316 SdHoareTripleChecker+Valid, 5.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3277 mSDsluCounter, 3113 SdHoareTripleChecker+Invalid, 4.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2389 mSDsCounter, 1890 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 6716 IncrementalHoareTripleChecker+Invalid, 8606 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1890 mSolverCounterUnsat, 724 mSDtfsCounter, 6716 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 926 GetRequests, 528 SyntacticMatches, 15 SemanticMatches, 383 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12937 ImplicationChecksByTransitivity, 87.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1611occurred in iteration=8, InterpolantAutomatonStates: 255, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 1.1s AutomataMinimizationTime, 12 MinimizatonAttempts, 937 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 36 LocationsWithAnnotation, 4619 PreInvPairs, 5629 NumberOfFragments, 3471 HoareAnnotationTreeSize, 4619 FomulaSimplifications, 86850 FormulaSimplificationTreeSizeReduction, 5.2s HoareSimplificationTime, 36 FomulaSimplificationsInter, 166040 FormulaSimplificationTreeSizeReductionInter, 21.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 5.3s InterpolantComputationTime, 736 NumberOfCodeBlocks, 736 NumberOfCodeBlocksAsserted, 18 NumberOfCheckSat, 875 ConstructedInterpolants, 0 QuantifiedInterpolants, 2600 SizeOfPredicates, 62 NumberOfNonLiveVariables, 2103 ConjunctsInSsa, 137 ConjunctsInUnsatCore, 20 InterpolantComputations, 9 PerfectInterpolantSequences, 217/263 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 683]: Loop Invariant Derived loop invariant: ((((((((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && ((((tmp == 1 && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || ((pumpRunning == 0 && waterLevel <= \old(waterLevel)) && waterLevel < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && (((((((2 == waterLevel && 1 == systemActive) && methaneLevelCritical == 1) && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((!(\old(pumpRunning) == 0) || (((2 == waterLevel && 1 == systemActive) && methaneLevelCritical == 1) && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || (2 <= waterLevel && pumpRunning == 1)) || waterLevel == 1)) && ((((methaneLevelCritical == tmp && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3))) && (((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1)) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 52]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 140]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 839]: Loop Invariant Derived loop invariant: (((((((((((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && waterLevel <= \old(waterLevel))) || pumpRunning == 1) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || waterLevel <= \old(waterLevel))) && (((((!(1 == systemActive) || ((pumpRunning == 0 && waterLevel <= \old(waterLevel)) && waterLevel < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && ((((((waterLevel == 1 && pumpRunning == 1) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || waterLevel <= \old(waterLevel))) && (((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || waterLevel == 1) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) - InvariantResult [Line: 140]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && tmp == 1) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 781]: Loop Invariant Derived loop invariant: ((((((((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) < 3)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || \old(waterLevel) == waterLevel)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 718]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 847]: Loop Invariant Derived loop invariant: (((((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(methaneLevelCritical == 0)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && (!(2 <= tmp___0) || !(pumpRunning == 0))) && waterLevel < 2)) || !(\old(waterLevel) < 3))) && (((!(1 == systemActive) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) && (!(2 <= tmp___0) || !(pumpRunning == 0))) && waterLevel < 2)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1) - InvariantResult [Line: 843]: Loop Invariant Derived loop invariant: (((((((((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) < 3))) && (((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || (!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || pumpRunning == 1) - InvariantResult [Line: 674]: Loop Invariant Derived loop invariant: ((((((((((((((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (pumpRunning == 0 && 1 == systemActive)) || !(\old(waterLevel) < 3)) || pumpRunning == 1) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == tmp && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || ((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel == 1)) || !(\old(waterLevel) == 2))) && (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || (pumpRunning == 0 && 1 == systemActive)) || !(\old(waterLevel) < 3)) || pumpRunning == 1)) && (((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) || waterLevel <= \old(waterLevel))) && ((((!(\old(waterLevel) <= 1) || ((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel)) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && (((((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel <= \old(waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel)) && (((!(1 == systemActive) || !(methaneLevelCritical == 1)) || (tmp == 1 && waterLevel < 3)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || 2 <= waterLevel) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || waterLevel == 1)) && ((((((pumpRunning == 0 && 1 == systemActive) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 719]: Loop Invariant Derived loop invariant: ((((((2 == waterLevel && methaneLevelCritical == 0) && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && pumpRunning == 1) || ((((methaneLevelCritical == 0 && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel < 2)) || ((((tmp == 1 && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && waterLevel < 3) - InvariantResult [Line: 817]: Loop Invariant Derived loop invariant: ((((((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(waterLevel <= 1))) && (((((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || pumpRunning == 1)) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (!(waterLevel < 2) && \old(pumpRunning) == 0))) && (((((!(1 == systemActive) || !(waterLevel < 2)) || !(\old(pumpRunning) == 1)) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || !(methaneLevelCritical == 1)) || pumpRunning == 1)) && (((((!(waterLevel == 1) || !(pumpRunning == 0)) || !(1 == systemActive)) || \old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || (!(waterLevel < 2) && \old(pumpRunning) == 0))) && (((((!(waterLevel == 1) || !(pumpRunning == 0)) || !(1 == systemActive)) || \old(pumpRunning) == 0) || (!(waterLevel < 2) && \old(pumpRunning) == 0)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 739]: Loop Invariant Derived loop invariant: ((((methaneLevelCritical == 0 && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel < 3) || ((((tmp == 1 && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && waterLevel < 3) - InvariantResult [Line: 689]: Loop Invariant Derived loop invariant: ((((((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3)) && ((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2)) || \old(waterLevel) == waterLevel) || waterLevel == 1)) && (((((((methaneLevelCritical == tmp && tmp___0 <= 1) && waterLevel <= \old(waterLevel)) && waterLevel < 2) || !(1 == systemActive)) || (((methaneLevelCritical == tmp && 2 <= waterLevel) && waterLevel <= \old(waterLevel)) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) < 3))) && (((((pumpRunning == 0 || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) < 3)) || (waterLevel < 2 && pumpRunning == 1))) && ((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || tmp___0 == 1)) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) - InvariantResult [Line: 559]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 0)) && ((!(1 == systemActive) || !(\old(waterLevel) < 2)) || !(methaneLevelCritical == 1))) && ((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) - InvariantResult [Line: 903]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && tmp == 1) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) || !(waterLevel < 3))) && ((!(1 == systemActive) || !(waterLevel < 2)) || !(methaneLevelCritical == 1))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) || ((pumpRunning == 0 && tmp == 1) && aux-isMethaneLevelCritical()-aux == methaneLevelCritical)) - InvariantResult [Line: 709]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-11-16 16:10:16,308 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_68849558-ffde-458f-83f5-d77874b840d2/bin/utaipan-Xvt2sAort0/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE