./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 8393723b Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 1ef39c14b0f41147d1df64069011556a64ce74ff520b071f62407c2225292c50 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-8393723 [2022-11-19 08:27:15,725 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-19 08:27:15,728 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-19 08:27:15,774 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-19 08:27:15,776 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-19 08:27:15,780 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-19 08:27:15,783 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-19 08:27:15,786 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-19 08:27:15,790 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-19 08:27:15,799 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-19 08:27:15,800 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-19 08:27:15,802 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-19 08:27:15,803 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-19 08:27:15,805 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-19 08:27:15,807 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-19 08:27:15,808 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-19 08:27:15,810 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-19 08:27:15,811 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-19 08:27:15,813 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-19 08:27:15,816 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-19 08:27:15,820 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-19 08:27:15,822 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-19 08:27:15,826 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-19 08:27:15,827 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-19 08:27:15,837 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-19 08:27:15,839 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-19 08:27:15,839 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-19 08:27:15,840 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-19 08:27:15,842 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-19 08:27:15,843 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-19 08:27:15,844 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-19 08:27:15,845 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-19 08:27:15,847 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-19 08:27:15,849 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-19 08:27:15,850 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-19 08:27:15,850 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-19 08:27:15,851 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-19 08:27:15,852 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-19 08:27:15,852 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-19 08:27:15,853 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-19 08:27:15,854 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-19 08:27:15,855 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-19 08:27:15,903 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-19 08:27:15,903 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-19 08:27:15,904 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-19 08:27:15,904 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-19 08:27:15,906 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-19 08:27:15,906 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-19 08:27:15,906 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-19 08:27:15,906 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-19 08:27:15,907 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-19 08:27:15,907 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-19 08:27:15,908 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-19 08:27:15,908 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-19 08:27:15,909 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-19 08:27:15,909 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-19 08:27:15,909 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-19 08:27:15,910 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-19 08:27:15,910 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-19 08:27:15,910 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-19 08:27:15,911 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-19 08:27:15,911 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-19 08:27:15,911 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-19 08:27:15,912 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-19 08:27:15,912 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-19 08:27:15,914 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-19 08:27:15,914 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-19 08:27:15,914 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-19 08:27:15,914 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-19 08:27:15,915 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-19 08:27:15,915 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-19 08:27:15,915 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-19 08:27:15,916 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-19 08:27:15,916 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-19 08:27:15,916 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 08:27:15,917 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-19 08:27:15,917 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-19 08:27:15,917 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-19 08:27:15,918 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-19 08:27:15,918 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-19 08:27:15,918 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-19 08:27:15,918 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-19 08:27:15,919 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-19 08:27:15,919 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 1ef39c14b0f41147d1df64069011556a64ce74ff520b071f62407c2225292c50 [2022-11-19 08:27:16,195 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-19 08:27:16,244 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-19 08:27:16,250 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-19 08:27:16,252 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-19 08:27:16,253 INFO L275 PluginConnector]: CDTParser initialized [2022-11-19 08:27:16,254 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/../../sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c [2022-11-19 08:27:16,338 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/data/3b04bd8d0/895e0874fb7348ef842e8feccccf7616/FLAG576b0bc25 [2022-11-19 08:27:17,057 INFO L306 CDTParser]: Found 1 translation units. [2022-11-19 08:27:17,058 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c [2022-11-19 08:27:17,071 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/data/3b04bd8d0/895e0874fb7348ef842e8feccccf7616/FLAG576b0bc25 [2022-11-19 08:27:17,088 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/data/3b04bd8d0/895e0874fb7348ef842e8feccccf7616 [2022-11-19 08:27:17,091 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-19 08:27:17,092 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-19 08:27:17,096 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-19 08:27:17,096 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-19 08:27:17,101 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-19 08:27:17,102 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,104 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@b2f47b6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17, skipping insertion in model container [2022-11-19 08:27:17,104 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,112 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-19 08:27:17,175 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-19 08:27:17,536 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c[18485,18498] [2022-11-19 08:27:17,553 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 08:27:17,563 INFO L203 MainTranslator]: Completed pre-run [2022-11-19 08:27:17,667 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/sv-benchmarks/c/product-lines/minepump_spec5_product51.cil.c[18485,18498] [2022-11-19 08:27:17,671 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 08:27:17,697 INFO L208 MainTranslator]: Completed translation [2022-11-19 08:27:17,697 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17 WrapperNode [2022-11-19 08:27:17,698 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-19 08:27:17,699 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-19 08:27:17,699 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-19 08:27:17,700 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-19 08:27:17,708 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,722 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,759 INFO L138 Inliner]: procedures = 58, calls = 103, calls flagged for inlining = 25, calls inlined = 21, statements flattened = 209 [2022-11-19 08:27:17,759 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-19 08:27:17,760 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-19 08:27:17,760 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-19 08:27:17,760 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-19 08:27:17,770 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,771 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,773 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,774 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,779 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,784 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,785 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,787 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,790 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-19 08:27:17,791 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-19 08:27:17,795 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-19 08:27:17,795 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-19 08:27:17,796 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (1/1) ... [2022-11-19 08:27:17,808 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 08:27:17,823 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 08:27:17,837 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-19 08:27:17,855 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-19 08:27:17,886 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-19 08:27:17,886 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-19 08:27:17,887 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-19 08:27:17,887 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-19 08:27:17,887 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-19 08:27:17,887 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-19 08:27:17,887 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-19 08:27:17,888 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 08:27:17,888 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 08:27:17,888 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-19 08:27:17,888 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-19 08:27:17,888 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-19 08:27:17,889 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-19 08:27:17,889 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-19 08:27:17,889 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-19 08:27:17,889 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-19 08:27:17,889 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-19 08:27:17,890 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-19 08:27:17,890 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-19 08:27:17,890 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-19 08:27:17,981 INFO L235 CfgBuilder]: Building ICFG [2022-11-19 08:27:17,983 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-19 08:27:18,379 INFO L276 CfgBuilder]: Performing block encoding [2022-11-19 08:27:18,583 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-19 08:27:18,583 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-19 08:27:18,588 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 08:27:18 BoogieIcfgContainer [2022-11-19 08:27:18,589 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-19 08:27:18,591 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-19 08:27:18,592 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-19 08:27:18,595 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-19 08:27:18,596 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 19.11 08:27:17" (1/3) ... [2022-11-19 08:27:18,597 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@698605b6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 08:27:18, skipping insertion in model container [2022-11-19 08:27:18,597 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 08:27:17" (2/3) ... [2022-11-19 08:27:18,599 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@698605b6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 08:27:18, skipping insertion in model container [2022-11-19 08:27:18,600 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 08:27:18" (3/3) ... [2022-11-19 08:27:18,601 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product51.cil.c [2022-11-19 08:27:18,623 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-19 08:27:18,624 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-19 08:27:18,718 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-19 08:27:18,731 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@7c327f45, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-19 08:27:18,731 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-19 08:27:18,736 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-19 08:27:18,751 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-19 08:27:18,752 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:18,753 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:18,754 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:18,764 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:18,765 INFO L85 PathProgramCache]: Analyzing trace with hash -51587778, now seen corresponding path program 1 times [2022-11-19 08:27:18,777 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:18,779 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [723434753] [2022-11-19 08:27:18,779 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:18,780 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:18,932 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:19,050 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:19,051 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:19,051 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [723434753] [2022-11-19 08:27:19,052 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [723434753] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:19,052 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:19,052 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-19 08:27:19,054 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [32595078] [2022-11-19 08:27:19,055 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:19,062 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-19 08:27:19,064 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:19,101 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-19 08:27:19,102 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 08:27:19,107 INFO L87 Difference]: Start difference. First operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:19,183 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:19,184 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2022-11-19 08:27:19,185 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-19 08:27:19,187 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-19 08:27:19,187 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:19,197 INFO L225 Difference]: With dead ends: 130 [2022-11-19 08:27:19,198 INFO L226 Difference]: Without dead ends: 61 [2022-11-19 08:27:19,202 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 08:27:19,205 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 69 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:19,206 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 69 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-19 08:27:19,225 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-19 08:27:19,256 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-19 08:27:19,258 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 39 states have (on average 1.358974358974359) internal successors, (53), 47 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-19 08:27:19,260 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 80 transitions. [2022-11-19 08:27:19,262 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 80 transitions. Word has length 21 [2022-11-19 08:27:19,262 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:19,262 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 80 transitions. [2022-11-19 08:27:19,263 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:19,263 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 80 transitions. [2022-11-19 08:27:19,265 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-19 08:27:19,265 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:19,266 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:19,266 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-19 08:27:19,266 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:19,267 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:19,267 INFO L85 PathProgramCache]: Analyzing trace with hash -421310611, now seen corresponding path program 1 times [2022-11-19 08:27:19,267 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:19,268 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [918155680] [2022-11-19 08:27:19,268 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:19,268 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:19,286 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:19,374 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:19,374 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:19,375 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [918155680] [2022-11-19 08:27:19,375 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [918155680] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:19,375 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:19,375 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 08:27:19,376 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1631730765] [2022-11-19 08:27:19,376 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:19,377 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 08:27:19,377 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:19,378 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 08:27:19,378 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 08:27:19,379 INFO L87 Difference]: Start difference. First operand 61 states and 80 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:19,451 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:19,451 INFO L93 Difference]: Finished difference Result 94 states and 122 transitions. [2022-11-19 08:27:19,452 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 08:27:19,452 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-19 08:27:19,452 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:19,453 INFO L225 Difference]: With dead ends: 94 [2022-11-19 08:27:19,453 INFO L226 Difference]: Without dead ends: 53 [2022-11-19 08:27:19,454 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 08:27:19,456 INFO L413 NwaCegarLoop]: 55 mSDtfsCounter, 14 mSDsluCounter, 38 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 93 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:19,495 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 93 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 08:27:19,496 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-19 08:27:19,503 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-19 08:27:19,504 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3823529411764706) internal successors, (47), 42 states have internal predecessors, (47), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-19 08:27:19,505 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 69 transitions. [2022-11-19 08:27:19,505 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 69 transitions. Word has length 22 [2022-11-19 08:27:19,505 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:19,506 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 69 transitions. [2022-11-19 08:27:19,506 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:19,506 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 69 transitions. [2022-11-19 08:27:19,507 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-19 08:27:19,507 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:19,508 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:19,508 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-19 08:27:19,508 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:19,509 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:19,509 INFO L85 PathProgramCache]: Analyzing trace with hash -354328816, now seen corresponding path program 1 times [2022-11-19 08:27:19,509 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:19,509 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [804764973] [2022-11-19 08:27:19,509 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:19,510 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:19,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:19,793 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:19,794 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:19,794 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [804764973] [2022-11-19 08:27:19,794 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [804764973] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:19,794 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:19,795 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-19 08:27:19,795 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1172973535] [2022-11-19 08:27:19,795 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:19,796 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-19 08:27:19,796 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:19,796 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-19 08:27:19,796 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-19 08:27:19,797 INFO L87 Difference]: Start difference. First operand 53 states and 69 transitions. Second operand has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 08:27:19,969 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:19,970 INFO L93 Difference]: Finished difference Result 154 states and 207 transitions. [2022-11-19 08:27:19,970 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-19 08:27:19,971 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2022-11-19 08:27:19,971 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:19,972 INFO L225 Difference]: With dead ends: 154 [2022-11-19 08:27:19,973 INFO L226 Difference]: Without dead ends: 103 [2022-11-19 08:27:19,974 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-19 08:27:19,975 INFO L413 NwaCegarLoop]: 70 mSDtfsCounter, 81 mSDsluCounter, 93 mSDsCounter, 0 mSdLazyCounter, 71 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 81 SdHoareTripleChecker+Valid, 163 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 71 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:19,976 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [81 Valid, 163 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 71 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 08:27:19,977 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 103 states. [2022-11-19 08:27:19,992 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 103 to 86. [2022-11-19 08:27:19,993 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 56 states have (on average 1.375) internal successors, (77), 67 states have internal predecessors, (77), 17 states have call successors, (17), 12 states have call predecessors, (17), 12 states have return successors, (18), 13 states have call predecessors, (18), 17 states have call successors, (18) [2022-11-19 08:27:19,995 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 112 transitions. [2022-11-19 08:27:19,995 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 112 transitions. Word has length 25 [2022-11-19 08:27:19,996 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:19,996 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 112 transitions. [2022-11-19 08:27:19,996 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 08:27:19,996 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 112 transitions. [2022-11-19 08:27:19,998 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-19 08:27:19,998 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:19,998 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:19,998 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-19 08:27:19,999 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:19,999 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:20,000 INFO L85 PathProgramCache]: Analyzing trace with hash 1724918103, now seen corresponding path program 1 times [2022-11-19 08:27:20,000 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:20,000 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [268560545] [2022-11-19 08:27:20,000 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:20,001 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:20,017 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:20,139 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-19 08:27:20,140 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:20,140 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [268560545] [2022-11-19 08:27:20,140 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [268560545] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:20,140 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:20,141 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-19 08:27:20,141 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [513260092] [2022-11-19 08:27:20,141 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:20,142 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-19 08:27:20,142 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:20,142 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-19 08:27:20,143 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-19 08:27:20,143 INFO L87 Difference]: Start difference. First operand 86 states and 112 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:20,314 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:20,315 INFO L93 Difference]: Finished difference Result 209 states and 282 transitions. [2022-11-19 08:27:20,315 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-19 08:27:20,316 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2022-11-19 08:27:20,316 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:20,318 INFO L225 Difference]: With dead ends: 209 [2022-11-19 08:27:20,327 INFO L226 Difference]: Without dead ends: 125 [2022-11-19 08:27:20,329 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-19 08:27:20,330 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 35 mSDsluCounter, 216 mSDsCounter, 0 mSdLazyCounter, 117 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 283 SdHoareTripleChecker+Invalid, 125 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 117 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:20,331 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [36 Valid, 283 Invalid, 125 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 117 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 08:27:20,332 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 125 states. [2022-11-19 08:27:20,349 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 125 to 118. [2022-11-19 08:27:20,350 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 118 states, 79 states have (on average 1.2911392405063291) internal successors, (102), 89 states have internal predecessors, (102), 21 states have call successors, (21), 17 states have call predecessors, (21), 17 states have return successors, (27), 20 states have call predecessors, (27), 21 states have call successors, (27) [2022-11-19 08:27:20,351 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 118 states to 118 states and 150 transitions. [2022-11-19 08:27:20,352 INFO L78 Accepts]: Start accepts. Automaton has 118 states and 150 transitions. Word has length 28 [2022-11-19 08:27:20,352 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:20,352 INFO L495 AbstractCegarLoop]: Abstraction has 118 states and 150 transitions. [2022-11-19 08:27:20,353 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 08:27:20,353 INFO L276 IsEmpty]: Start isEmpty. Operand 118 states and 150 transitions. [2022-11-19 08:27:20,354 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-19 08:27:20,354 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:20,355 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:20,355 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-19 08:27:20,355 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:20,356 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:20,356 INFO L85 PathProgramCache]: Analyzing trace with hash -1342169840, now seen corresponding path program 1 times [2022-11-19 08:27:20,356 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:20,357 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1950212037] [2022-11-19 08:27:20,357 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:20,357 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:20,375 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:20,826 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:20,827 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:20,827 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1950212037] [2022-11-19 08:27:20,827 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1950212037] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:20,828 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:20,829 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-19 08:27:20,830 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1295830131] [2022-11-19 08:27:20,832 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:20,833 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-19 08:27:20,834 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:20,835 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-19 08:27:20,835 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-19 08:27:20,836 INFO L87 Difference]: Start difference. First operand 118 states and 150 transitions. Second operand has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-19 08:27:21,123 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:21,124 INFO L93 Difference]: Finished difference Result 370 states and 474 transitions. [2022-11-19 08:27:21,124 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-19 08:27:21,131 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 33 [2022-11-19 08:27:21,131 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:21,140 INFO L225 Difference]: With dead ends: 370 [2022-11-19 08:27:21,141 INFO L226 Difference]: Without dead ends: 254 [2022-11-19 08:27:21,143 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=20, Invalid=36, Unknown=0, NotChecked=0, Total=56 [2022-11-19 08:27:21,146 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 99 mSDsluCounter, 208 mSDsCounter, 0 mSdLazyCounter, 183 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 101 SdHoareTripleChecker+Valid, 300 SdHoareTripleChecker+Invalid, 196 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 183 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:21,147 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [101 Valid, 300 Invalid, 196 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 183 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 08:27:21,148 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 254 states. [2022-11-19 08:27:21,228 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 254 to 249. [2022-11-19 08:27:21,233 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 249 states, 166 states have (on average 1.2891566265060241) internal successors, (214), 185 states have internal predecessors, (214), 45 states have call successors, (45), 38 states have call predecessors, (45), 37 states have return successors, (59), 40 states have call predecessors, (59), 45 states have call successors, (59) [2022-11-19 08:27:21,242 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 249 states to 249 states and 318 transitions. [2022-11-19 08:27:21,242 INFO L78 Accepts]: Start accepts. Automaton has 249 states and 318 transitions. Word has length 33 [2022-11-19 08:27:21,242 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:21,243 INFO L495 AbstractCegarLoop]: Abstraction has 249 states and 318 transitions. [2022-11-19 08:27:21,243 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-19 08:27:21,243 INFO L276 IsEmpty]: Start isEmpty. Operand 249 states and 318 transitions. [2022-11-19 08:27:21,245 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-19 08:27:21,246 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:21,246 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:21,246 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-19 08:27:21,246 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:21,247 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:21,247 INFO L85 PathProgramCache]: Analyzing trace with hash -902427270, now seen corresponding path program 1 times [2022-11-19 08:27:21,247 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:21,247 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [652233628] [2022-11-19 08:27:21,248 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:21,248 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:21,285 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:21,641 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:21,642 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:21,642 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [652233628] [2022-11-19 08:27:21,642 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [652233628] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:21,642 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:21,642 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-19 08:27:21,643 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1599830635] [2022-11-19 08:27:21,643 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:21,643 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 08:27:21,644 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:21,644 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 08:27:21,645 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-19 08:27:21,645 INFO L87 Difference]: Start difference. First operand 249 states and 318 transitions. Second operand has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 08:27:22,257 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:22,258 INFO L93 Difference]: Finished difference Result 557 states and 734 transitions. [2022-11-19 08:27:22,258 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-19 08:27:22,259 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 36 [2022-11-19 08:27:22,259 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:22,263 INFO L225 Difference]: With dead ends: 557 [2022-11-19 08:27:22,263 INFO L226 Difference]: Without dead ends: 401 [2022-11-19 08:27:22,264 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 4 SyntacticMatches, 1 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 31 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-19 08:27:22,273 INFO L413 NwaCegarLoop]: 79 mSDtfsCounter, 235 mSDsluCounter, 190 mSDsCounter, 0 mSdLazyCounter, 306 mSolverCounterSat, 95 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 241 SdHoareTripleChecker+Valid, 269 SdHoareTripleChecker+Invalid, 401 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 95 IncrementalHoareTripleChecker+Valid, 306 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:22,276 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [241 Valid, 269 Invalid, 401 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [95 Valid, 306 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-19 08:27:22,279 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 401 states. [2022-11-19 08:27:22,333 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 401 to 347. [2022-11-19 08:27:22,334 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 347 states, 235 states have (on average 1.2808510638297872) internal successors, (301), 261 states have internal predecessors, (301), 60 states have call successors, (60), 47 states have call predecessors, (60), 51 states have return successors, (82), 58 states have call predecessors, (82), 60 states have call successors, (82) [2022-11-19 08:27:22,337 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 347 states to 347 states and 443 transitions. [2022-11-19 08:27:22,337 INFO L78 Accepts]: Start accepts. Automaton has 347 states and 443 transitions. Word has length 36 [2022-11-19 08:27:22,337 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:22,338 INFO L495 AbstractCegarLoop]: Abstraction has 347 states and 443 transitions. [2022-11-19 08:27:22,338 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 08:27:22,338 INFO L276 IsEmpty]: Start isEmpty. Operand 347 states and 443 transitions. [2022-11-19 08:27:22,340 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-19 08:27:22,340 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:22,341 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:22,341 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-19 08:27:22,341 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:22,342 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:22,342 INFO L85 PathProgramCache]: Analyzing trace with hash -1121294904, now seen corresponding path program 1 times [2022-11-19 08:27:22,342 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:22,342 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [784850307] [2022-11-19 08:27:22,342 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:22,343 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:22,356 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:22,394 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 17 proven. 0 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-19 08:27:22,394 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:22,395 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [784850307] [2022-11-19 08:27:22,395 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [784850307] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:22,395 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 08:27:22,395 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-19 08:27:22,395 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [920806993] [2022-11-19 08:27:22,396 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:22,396 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-19 08:27:22,396 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:22,397 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-19 08:27:22,397 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-19 08:27:22,397 INFO L87 Difference]: Start difference. First operand 347 states and 443 transitions. Second operand has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-19 08:27:22,533 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:22,533 INFO L93 Difference]: Finished difference Result 698 states and 890 transitions. [2022-11-19 08:27:22,534 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-11-19 08:27:22,534 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) Word has length 65 [2022-11-19 08:27:22,534 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:22,537 INFO L225 Difference]: With dead ends: 698 [2022-11-19 08:27:22,537 INFO L226 Difference]: Without dead ends: 247 [2022-11-19 08:27:22,539 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 2 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-19 08:27:22,544 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 94 mSDsluCounter, 48 mSDsCounter, 0 mSdLazyCounter, 80 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 94 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 82 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 80 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:22,545 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [94 Valid, 128 Invalid, 82 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 80 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 08:27:22,547 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 247 states. [2022-11-19 08:27:22,582 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 247 to 247. [2022-11-19 08:27:22,583 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 247 states, 167 states have (on average 1.2395209580838322) internal successors, (207), 184 states have internal predecessors, (207), 42 states have call successors, (42), 32 states have call predecessors, (42), 37 states have return successors, (57), 42 states have call predecessors, (57), 42 states have call successors, (57) [2022-11-19 08:27:22,587 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 247 states to 247 states and 306 transitions. [2022-11-19 08:27:22,587 INFO L78 Accepts]: Start accepts. Automaton has 247 states and 306 transitions. Word has length 65 [2022-11-19 08:27:22,588 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:22,588 INFO L495 AbstractCegarLoop]: Abstraction has 247 states and 306 transitions. [2022-11-19 08:27:22,588 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 3 states have (on average 14.666666666666666) internal successors, (44), 4 states have internal predecessors, (44), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 4 states have call successors, (7) [2022-11-19 08:27:22,588 INFO L276 IsEmpty]: Start isEmpty. Operand 247 states and 306 transitions. [2022-11-19 08:27:22,590 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2022-11-19 08:27:22,590 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:22,591 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:22,591 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-19 08:27:22,591 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:22,592 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:22,592 INFO L85 PathProgramCache]: Analyzing trace with hash 641510741, now seen corresponding path program 1 times [2022-11-19 08:27:22,592 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:22,592 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [644517044] [2022-11-19 08:27:22,593 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:22,593 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:22,624 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:22,749 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 17 proven. 2 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-19 08:27:22,749 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:22,753 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [644517044] [2022-11-19 08:27:22,753 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [644517044] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 08:27:22,753 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [601268532] [2022-11-19 08:27:22,754 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:22,754 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 08:27:22,755 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 08:27:22,763 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 08:27:22,770 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-19 08:27:22,894 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:22,898 INFO L263 TraceCheckSpWp]: Trace formula consists of 302 conjuncts, 4 conjunts are in the unsatisfiable core [2022-11-19 08:27:22,908 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 08:27:23,058 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-19 08:27:23,058 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-19 08:27:23,059 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [601268532] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 08:27:23,059 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-19 08:27:23,059 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [5] total 6 [2022-11-19 08:27:23,060 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1297941313] [2022-11-19 08:27:23,060 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 08:27:23,060 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 08:27:23,060 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:23,061 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 08:27:23,061 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2022-11-19 08:27:23,061 INFO L87 Difference]: Start difference. First operand 247 states and 306 transitions. Second operand has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-19 08:27:23,143 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:23,144 INFO L93 Difference]: Finished difference Result 369 states and 461 transitions. [2022-11-19 08:27:23,144 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 08:27:23,144 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 62 [2022-11-19 08:27:23,145 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:23,147 INFO L225 Difference]: With dead ends: 369 [2022-11-19 08:27:23,147 INFO L226 Difference]: Without dead ends: 237 [2022-11-19 08:27:23,148 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 68 GetRequests, 64 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2022-11-19 08:27:23,149 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 30 mSDsluCounter, 37 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 30 SdHoareTripleChecker+Valid, 113 SdHoareTripleChecker+Invalid, 32 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:23,149 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [30 Valid, 113 Invalid, 32 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 08:27:23,150 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2022-11-19 08:27:23,193 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 237. [2022-11-19 08:27:23,193 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 237 states, 160 states have (on average 1.2125) internal successors, (194), 176 states have internal predecessors, (194), 40 states have call successors, (40), 32 states have call predecessors, (40), 36 states have return successors, (47), 40 states have call predecessors, (47), 40 states have call successors, (47) [2022-11-19 08:27:23,195 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 237 states to 237 states and 281 transitions. [2022-11-19 08:27:23,196 INFO L78 Accepts]: Start accepts. Automaton has 237 states and 281 transitions. Word has length 62 [2022-11-19 08:27:23,196 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:23,197 INFO L495 AbstractCegarLoop]: Abstraction has 237 states and 281 transitions. [2022-11-19 08:27:23,197 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 15.666666666666666) internal successors, (47), 3 states have internal predecessors, (47), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-11-19 08:27:23,197 INFO L276 IsEmpty]: Start isEmpty. Operand 237 states and 281 transitions. [2022-11-19 08:27:23,198 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-19 08:27:23,198 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:23,198 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:23,213 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-19 08:27:23,413 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 08:27:23,413 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:23,414 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:23,414 INFO L85 PathProgramCache]: Analyzing trace with hash -1725898309, now seen corresponding path program 1 times [2022-11-19 08:27:23,414 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:23,414 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1661187812] [2022-11-19 08:27:23,414 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:23,415 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:23,461 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:23,638 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-19 08:27:23,639 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:23,639 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1661187812] [2022-11-19 08:27:23,639 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1661187812] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 08:27:23,639 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1905482831] [2022-11-19 08:27:23,640 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:23,640 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 08:27:23,640 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 08:27:23,643 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 08:27:23,682 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-19 08:27:23,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:23,761 INFO L263 TraceCheckSpWp]: Trace formula consists of 307 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-19 08:27:23,764 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 08:27:23,897 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 19 proven. 7 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-19 08:27:23,898 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 08:27:24,078 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 6 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2022-11-19 08:27:24,079 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1905482831] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 08:27:24,079 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [958089436] [2022-11-19 08:27:24,100 INFO L159 IcfgInterpreter]: Started Sifa with 42 locations of interest [2022-11-19 08:27:24,100 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 08:27:24,104 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 08:27:24,110 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 08:27:24,110 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 08:27:28,907 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 127 for LOIs [2022-11-19 08:27:28,930 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 29 for LOIs [2022-11-19 08:27:29,359 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2022-11-19 08:27:29,376 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 72 for LOIs [2022-11-19 08:27:29,719 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 48 for LOIs [2022-11-19 08:27:29,725 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 08:27:35,012 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '6741#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483647) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483648)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= 0 ~methaneLevelCritical~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 08:27:35,013 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 08:27:35,013 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 08:27:35,013 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 13 [2022-11-19 08:27:35,014 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [312588699] [2022-11-19 08:27:35,014 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 08:27:35,014 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-19 08:27:35,015 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:35,015 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-19 08:27:35,016 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=210, Invalid=1770, Unknown=0, NotChecked=0, Total=1980 [2022-11-19 08:27:35,016 INFO L87 Difference]: Start difference. First operand 237 states and 281 transitions. Second operand has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-19 08:27:35,732 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:35,733 INFO L93 Difference]: Finished difference Result 308 states and 374 transitions. [2022-11-19 08:27:35,733 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-11-19 08:27:35,733 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) Word has length 65 [2022-11-19 08:27:35,734 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:35,735 INFO L225 Difference]: With dead ends: 308 [2022-11-19 08:27:35,736 INFO L226 Difference]: Without dead ends: 306 [2022-11-19 08:27:35,737 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 225 GetRequests, 163 SyntacticMatches, 4 SemanticMatches, 58 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1186 ImplicationChecksByTransitivity, 5.6s TimeCoverageRelationStatistics Valid=339, Invalid=3201, Unknown=0, NotChecked=0, Total=3540 [2022-11-19 08:27:35,738 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 169 mSDsluCounter, 654 mSDsCounter, 0 mSdLazyCounter, 417 mSolverCounterSat, 89 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 176 SdHoareTripleChecker+Valid, 780 SdHoareTripleChecker+Invalid, 506 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 89 IncrementalHoareTripleChecker+Valid, 417 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:35,738 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [176 Valid, 780 Invalid, 506 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [89 Valid, 417 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-19 08:27:35,739 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2022-11-19 08:27:35,764 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 285. [2022-11-19 08:27:35,765 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 191 states have (on average 1.2041884816753927) internal successors, (230), 212 states have internal predecessors, (230), 49 states have call successors, (49), 40 states have call predecessors, (49), 44 states have return successors, (60), 48 states have call predecessors, (60), 49 states have call successors, (60) [2022-11-19 08:27:35,767 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 339 transitions. [2022-11-19 08:27:35,767 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 339 transitions. Word has length 65 [2022-11-19 08:27:35,768 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:35,768 INFO L495 AbstractCegarLoop]: Abstraction has 285 states and 339 transitions. [2022-11-19 08:27:35,768 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 10 states have (on average 7.9) internal successors, (79), 11 states have internal predecessors, (79), 5 states have call successors, (17), 4 states have call predecessors, (17), 7 states have return successors, (17), 8 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-19 08:27:35,768 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 339 transitions. [2022-11-19 08:27:35,770 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 87 [2022-11-19 08:27:35,770 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:35,770 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:35,781 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-19 08:27:35,976 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2022-11-19 08:27:35,976 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:35,977 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:35,977 INFO L85 PathProgramCache]: Analyzing trace with hash -932444730, now seen corresponding path program 1 times [2022-11-19 08:27:35,977 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:35,977 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [189878797] [2022-11-19 08:27:35,977 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:35,977 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:35,996 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:36,256 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 35 proven. 3 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-11-19 08:27:36,256 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:36,257 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [189878797] [2022-11-19 08:27:36,257 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [189878797] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 08:27:36,257 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1933530835] [2022-11-19 08:27:36,257 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:36,257 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 08:27:36,258 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 08:27:36,259 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 08:27:36,283 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-19 08:27:36,396 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:36,398 INFO L263 TraceCheckSpWp]: Trace formula consists of 390 conjuncts, 18 conjunts are in the unsatisfiable core [2022-11-19 08:27:36,405 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 08:27:36,739 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 61 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-19 08:27:36,740 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 08:27:37,122 INFO L134 CoverageAnalysis]: Checked inductivity of 68 backedges. 48 proven. 3 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-19 08:27:37,122 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1933530835] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 08:27:37,122 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1530784996] [2022-11-19 08:27:37,129 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-19 08:27:37,130 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 08:27:37,130 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 08:27:37,130 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 08:27:37,130 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 08:27:40,684 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 129 for LOIs [2022-11-19 08:27:40,701 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-19 08:27:41,028 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 40 for LOIs [2022-11-19 08:27:41,033 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 08:27:41,052 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 34 for LOIs [2022-11-19 08:27:41,058 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 08:27:46,233 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '8233#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 08:27:46,233 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 08:27:46,234 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 08:27:46,234 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 9] total 20 [2022-11-19 08:27:46,234 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [820452166] [2022-11-19 08:27:46,234 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 08:27:46,235 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-19 08:27:46,235 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:46,235 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-19 08:27:46,236 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=283, Invalid=2369, Unknown=0, NotChecked=0, Total=2652 [2022-11-19 08:27:46,237 INFO L87 Difference]: Start difference. First operand 285 states and 339 transitions. Second operand has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-19 08:27:48,142 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:27:48,142 INFO L93 Difference]: Finished difference Result 848 states and 1107 transitions. [2022-11-19 08:27:48,142 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-19 08:27:48,143 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) Word has length 86 [2022-11-19 08:27:48,144 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:27:48,148 INFO L225 Difference]: With dead ends: 848 [2022-11-19 08:27:48,148 INFO L226 Difference]: Without dead ends: 557 [2022-11-19 08:27:48,151 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 311 GetRequests, 234 SyntacticMatches, 0 SemanticMatches, 77 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2065 ImplicationChecksByTransitivity, 6.2s TimeCoverageRelationStatistics Valid=655, Invalid=5507, Unknown=0, NotChecked=0, Total=6162 [2022-11-19 08:27:48,152 INFO L413 NwaCegarLoop]: 72 mSDtfsCounter, 473 mSDsluCounter, 595 mSDsCounter, 0 mSdLazyCounter, 1316 mSolverCounterSat, 319 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 476 SdHoareTripleChecker+Valid, 667 SdHoareTripleChecker+Invalid, 1635 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 319 IncrementalHoareTripleChecker+Valid, 1316 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-11-19 08:27:48,153 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [476 Valid, 667 Invalid, 1635 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [319 Valid, 1316 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-11-19 08:27:48,154 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 557 states. [2022-11-19 08:27:48,192 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 557 to 346. [2022-11-19 08:27:48,193 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 346 states, 233 states have (on average 1.167381974248927) internal successors, (272), 255 states have internal predecessors, (272), 56 states have call successors, (56), 50 states have call predecessors, (56), 56 states have return successors, (71), 57 states have call predecessors, (71), 56 states have call successors, (71) [2022-11-19 08:27:48,195 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 346 states to 346 states and 399 transitions. [2022-11-19 08:27:48,196 INFO L78 Accepts]: Start accepts. Automaton has 346 states and 399 transitions. Word has length 86 [2022-11-19 08:27:48,196 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:27:48,196 INFO L495 AbstractCegarLoop]: Abstraction has 346 states and 399 transitions. [2022-11-19 08:27:48,197 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 5.35) internal successors, (107), 20 states have internal predecessors, (107), 9 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (22), 10 states have call predecessors, (22), 9 states have call successors, (22) [2022-11-19 08:27:48,197 INFO L276 IsEmpty]: Start isEmpty. Operand 346 states and 399 transitions. [2022-11-19 08:27:48,199 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2022-11-19 08:27:48,199 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 08:27:48,199 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:27:48,206 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-19 08:27:48,405 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-19 08:27:48,406 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 08:27:48,406 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 08:27:48,406 INFO L85 PathProgramCache]: Analyzing trace with hash -57351158, now seen corresponding path program 1 times [2022-11-19 08:27:48,407 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 08:27:48,407 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [521744300] [2022-11-19 08:27:48,407 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:48,407 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 08:27:48,428 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:49,476 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 26 proven. 31 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-19 08:27:49,476 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 08:27:49,476 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [521744300] [2022-11-19 08:27:49,476 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [521744300] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 08:27:49,476 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1847264153] [2022-11-19 08:27:49,477 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 08:27:49,477 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 08:27:49,477 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 08:27:49,478 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 08:27:49,504 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-19 08:27:49,603 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 08:27:49,609 INFO L263 TraceCheckSpWp]: Trace formula consists of 404 conjuncts, 34 conjunts are in the unsatisfiable core [2022-11-19 08:27:49,613 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 08:27:50,149 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 23 proven. 54 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 08:27:50,150 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 08:27:50,874 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 52 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-19 08:27:50,874 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1847264153] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 08:27:50,874 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [560496461] [2022-11-19 08:27:50,877 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-19 08:27:50,877 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 08:27:50,877 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 08:27:50,877 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 08:27:50,878 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 08:27:53,646 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 55 for LOIs [2022-11-19 08:27:53,655 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-19 08:27:54,054 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 40 for LOIs [2022-11-19 08:27:54,060 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 08:27:54,082 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 34 for LOIs [2022-11-19 08:27:54,085 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 08:27:59,514 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '10699#(and (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (<= |old(~pumpRunning~0)| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 08:27:59,514 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 08:27:59,514 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 08:27:59,514 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [19, 13, 11] total 35 [2022-11-19 08:27:59,514 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1306608476] [2022-11-19 08:27:59,515 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 08:27:59,515 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 35 states [2022-11-19 08:27:59,515 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 08:27:59,516 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 35 interpolants. [2022-11-19 08:27:59,517 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=455, Invalid=3835, Unknown=0, NotChecked=0, Total=4290 [2022-11-19 08:27:59,517 INFO L87 Difference]: Start difference. First operand 346 states and 399 transitions. Second operand has 35 states, 35 states have (on average 4.771428571428571) internal successors, (167), 35 states have internal predecessors, (167), 18 states have call successors, (33), 9 states have call predecessors, (33), 13 states have return successors, (31), 19 states have call predecessors, (31), 17 states have call successors, (31) [2022-11-19 08:28:03,600 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 08:28:03,600 INFO L93 Difference]: Finished difference Result 857 states and 1019 transitions. [2022-11-19 08:28:03,600 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 46 states. [2022-11-19 08:28:03,601 INFO L78 Accepts]: Start accepts. Automaton has has 35 states, 35 states have (on average 4.771428571428571) internal successors, (167), 35 states have internal predecessors, (167), 18 states have call successors, (33), 9 states have call predecessors, (33), 13 states have return successors, (31), 19 states have call predecessors, (31), 17 states have call successors, (31) Word has length 91 [2022-11-19 08:28:03,601 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 08:28:03,601 INFO L225 Difference]: With dead ends: 857 [2022-11-19 08:28:03,602 INFO L226 Difference]: Without dead ends: 0 [2022-11-19 08:28:03,606 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 364 GetRequests, 252 SyntacticMatches, 4 SemanticMatches, 108 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4132 ImplicationChecksByTransitivity, 8.0s TimeCoverageRelationStatistics Valid=1447, Invalid=10543, Unknown=0, NotChecked=0, Total=11990 [2022-11-19 08:28:03,607 INFO L413 NwaCegarLoop]: 121 mSDtfsCounter, 1264 mSDsluCounter, 1048 mSDsCounter, 0 mSdLazyCounter, 2151 mSolverCounterSat, 936 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1264 SdHoareTripleChecker+Valid, 1169 SdHoareTripleChecker+Invalid, 3087 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 936 IncrementalHoareTripleChecker+Valid, 2151 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.8s IncrementalHoareTripleChecker+Time [2022-11-19 08:28:03,607 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1264 Valid, 1169 Invalid, 3087 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [936 Valid, 2151 Invalid, 0 Unknown, 0 Unchecked, 1.8s Time] [2022-11-19 08:28:03,608 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-19 08:28:03,608 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-19 08:28:03,608 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-19 08:28:03,608 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-19 08:28:03,608 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2022-11-19 08:28:03,608 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 08:28:03,608 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-19 08:28:03,609 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 35 states, 35 states have (on average 4.771428571428571) internal successors, (167), 35 states have internal predecessors, (167), 18 states have call successors, (33), 9 states have call predecessors, (33), 13 states have return successors, (31), 19 states have call predecessors, (31), 17 states have call successors, (31) [2022-11-19 08:28:03,609 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-19 08:28:03,609 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-19 08:28:03,612 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-19 08:28:03,624 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-11-19 08:28:03,824 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-19 08:28:03,826 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-19 08:28:11,694 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 160 167) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 08:28:11,694 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 160 167) no Hoare annotation was computed. [2022-11-19 08:28:11,695 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 93 99) no Hoare annotation was computed. [2022-11-19 08:28:11,695 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 93 99) the Hoare annotation is: true [2022-11-19 08:28:11,695 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 877 888) the Hoare annotation is: true [2022-11-19 08:28:11,695 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 877 888) no Hoare annotation was computed. [2022-11-19 08:28:11,695 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 279 308) no Hoare annotation was computed. [2022-11-19 08:28:11,696 INFO L902 garLoopResultBuilder]: At program point L289-2(lines 289 303) the Hoare annotation is: true [2022-11-19 08:28:11,696 INFO L902 garLoopResultBuilder]: At program point L285(line 285) the Hoare annotation is: true [2022-11-19 08:28:11,696 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 279 308) the Hoare annotation is: true [2022-11-19 08:28:11,696 INFO L899 garLoopResultBuilder]: For program point L285-1(line 285) no Hoare annotation was computed. [2022-11-19 08:28:11,696 INFO L902 garLoopResultBuilder]: At program point L304(lines 279 308) the Hoare annotation is: true [2022-11-19 08:28:11,696 INFO L899 garLoopResultBuilder]: For program point L300(line 300) no Hoare annotation was computed. [2022-11-19 08:28:11,697 INFO L899 garLoopResultBuilder]: For program point L293(lines 293 297) no Hoare annotation was computed. [2022-11-19 08:28:11,697 INFO L902 garLoopResultBuilder]: At program point L293-1(lines 293 297) the Hoare annotation is: true [2022-11-19 08:28:11,697 INFO L895 garLoopResultBuilder]: At program point L977(line 977) the Hoare annotation is: (let ((.cse8 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (= 0 ~systemActive~0))) (.cse9 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse10 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse12 (not (= |old(~waterLevel~0)| 2))) (.cse3 (and .cse6 (= ~pumpRunning~0 1))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse11 (and .cse8 .cse6)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 (not (<= 2 |old(~waterLevel~0)|))) (or .cse5 .cse7 (and .cse8 (or .cse6 (= ~waterLevel~0 1)))) (or .cse1 .cse2 .cse9 .cse4 .cse10) (or .cse5 .cse11 .cse1 .cse12) (or .cse5 .cse1 .cse9 .cse4 .cse10) (or .cse1 .cse2 .cse12 .cse3) (or .cse0 .cse5 .cse11 .cse1)))) [2022-11-19 08:28:11,698 INFO L895 garLoopResultBuilder]: At program point L977-1(line 977) the Hoare annotation is: (let ((.cse8 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (and .cse6 (<= 1 |timeShift___utac_acc__Specification5_spec__2_#t~ret51#1|) (= ~pumpRunning~0 1))) (.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse7 (not (= 0 ~systemActive~0))) (.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (and .cse8 .cse6)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse2 .cse3 .cse4) (or .cse5 (not (< 1 |old(~waterLevel~0)|)) .cse6 (not (<= |old(~waterLevel~0)| 2)) .cse7) (or .cse5 .cse7 (and .cse8 (or .cse6 (= ~waterLevel~0 1)))) (or .cse5 .cse9 .cse2 .cse4) (or .cse1 .cse5 .cse9 .cse2)))) [2022-11-19 08:28:11,698 INFO L899 garLoopResultBuilder]: For program point L73-2(lines 69 91) no Hoare annotation was computed. [2022-11-19 08:28:11,698 INFO L899 garLoopResultBuilder]: For program point L135(lines 135 143) no Hoare annotation was computed. [2022-11-19 08:28:11,698 INFO L895 garLoopResultBuilder]: At program point L131(lines 131 148) the Hoare annotation is: (let ((.cse8 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse4 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse6 (and (= ~pumpRunning~0 0) .cse8)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) .cse4) (or .cse5 .cse6 .cse0 .cse4) (or .cse7 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) .cse8) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse7 .cse5 .cse6 .cse0) (or .cse5 (not (= 0 ~systemActive~0)))))) [2022-11-19 08:28:11,699 INFO L899 garLoopResultBuilder]: For program point L994(lines 994 1004) no Hoare annotation was computed. [2022-11-19 08:28:11,699 INFO L899 garLoopResultBuilder]: For program point L990(lines 990 1007) no Hoare annotation was computed. [2022-11-19 08:28:11,699 INFO L895 garLoopResultBuilder]: At program point L990-1(lines 982 1010) the Hoare annotation is: (let ((.cse10 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse6 (not (= |old(~waterLevel~0)| 1))) (.cse13 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 2)) (.cse12 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| ~waterLevel~0)) (.cse14 (= ~waterLevel~0 1)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse9 (not (= |old(~pumpRunning~0)| 1))) (.cse11 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0)) (.cse5 (not (= 0 ~systemActive~0))) (.cse15 (not (= |old(~waterLevel~0)| 2))) (.cse8 (= ~pumpRunning~0 1))) (and (let ((.cse1 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse2 (< 0 |old(~waterLevel~0)|))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) .cse6 .cse7 (and .cse1 .cse2 .cse3 .cse4 .cse8) .cse9 .cse10)) (or .cse11 .cse0 .cse5) (or (and .cse12 .cse13) .cse11 (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2)) .cse5) (or .cse7 (and .cse3 .cse12 .cse4 .cse8) .cse9 (and .cse0 .cse3 .cse12 .cse4 .cse5) (not (<= |old(~waterLevel~0)| 0)) .cse10) (or .cse11 .cse6 .cse14 .cse5) (or (and .cse3 .cse12 .cse13) .cse11 .cse7 (and .cse0 .cse3 .cse12 .cse5) (not (< |old(~waterLevel~0)| 3))) (or (and .cse0 .cse3 .cse14 .cse4 .cse5) .cse7 (and .cse3 .cse14 .cse4 .cse8) .cse9 .cse15) (or .cse11 .cse7 (and .cse0 .cse5) .cse15 .cse8))) [2022-11-19 08:28:11,700 INFO L899 garLoopResultBuilder]: For program point L995(lines 995 1001) no Hoare annotation was computed. [2022-11-19 08:28:11,700 INFO L895 garLoopResultBuilder]: At program point L958(line 958) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (< |old(~waterLevel~0)| 3))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 2))) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2) (or .cse3 .cse0 .cse2) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-19 08:28:11,700 INFO L895 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse4 (not (= 0 ~systemActive~0))))) [2022-11-19 08:28:11,701 INFO L895 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 .cse0 (not (< |old(~waterLevel~0)| 3))) (or .cse4 (not (= 0 ~systemActive~0))))) [2022-11-19 08:28:11,701 INFO L895 garLoopResultBuilder]: At program point L992(line 992) the Hoare annotation is: (let ((.cse10 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= ~waterLevel~0 1)) (.cse5 (not (= 0 ~systemActive~0))) (.cse4 (not (= 1 ~systemActive~0))) (.cse8 (= ~pumpRunning~0 1)) (.cse9 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| ~waterLevel~0)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse7 (<= 1 ~switchedOnBeforeTS~0))) (and (or .cse0 (and .cse1 .cse2 .cse3) .cse4 (not (< |old(~waterLevel~0)| 3))) (or .cse0 .cse1 .cse5) (or .cse4 (and .cse2 .cse6 .cse7 .cse8) .cse9 (and .cse1 .cse2 .cse6 .cse7) .cse10) (or .cse0 .cse4 .cse10) (or .cse0 (not (< 1 |old(~waterLevel~0)|)) (not (<= |old(~waterLevel~0)| 2)) .cse5) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse6 .cse5) (let ((.cse12 (< 0 |old(~waterLevel~0)|))) (let ((.cse11 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse12))) (or (not (<= |old(~waterLevel~0)| 1)) .cse4 (and (<= ~waterLevel~0 0) .cse2 (or .cse11 .cse3) .cse7 .cse8) .cse9 (and .cse1 .cse2 (or (and (not .cse12) .cse3) .cse11) .cse7) (not (<= 1 |old(~switchedOnBeforeTS~0)|))))))) [2022-11-19 08:28:11,701 INFO L899 garLoopResultBuilder]: For program point L992-1(line 992) no Hoare annotation was computed. [2022-11-19 08:28:11,702 INFO L895 garLoopResultBuilder]: At program point L146(line 146) the Hoare annotation is: (let ((.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse4 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0 .cse2) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3))) (or (not (<= |old(~waterLevel~0)| 1)) .cse3 .cse4 .cse0) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-19 08:28:11,702 INFO L895 garLoopResultBuilder]: At program point L146-1(lines 127 151) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse12 (and .cse6 .cse9)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= ~pumpRunning~0 1)) (.cse11 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse2 (= ~waterLevel~0 1))) (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (and .cse6 .cse2 .cse3))) (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (let ((.cse8 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse10))) (or .cse7 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or .cse8 .cse9) .cse3 .cse4) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse6 (or (and (not .cse10) .cse9) .cse8) .cse3)))) (or .cse7 .cse11 .cse12 .cse0) (or .cse11 .cse12 .cse0 .cse5 (and .cse9 .cse4)) (or .cse11 (not (= 0 ~systemActive~0)))))) [2022-11-19 08:28:11,702 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 66 92) the Hoare annotation is: (let ((.cse8 (= ~pumpRunning~0 0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse7 (not (= 0 ~systemActive~0))) (.cse9 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse10 (not (< |old(~waterLevel~0)| 3))) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse12 (not (= |old(~waterLevel~0)| 2))) (.cse3 (and .cse6 (= ~pumpRunning~0 1))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse11 (and .cse8 .cse6)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 (not (<= 2 |old(~waterLevel~0)|))) (or .cse5 .cse7 (and .cse8 (or .cse6 (= ~waterLevel~0 1)))) (or .cse1 .cse2 .cse9 .cse4 .cse10) (or .cse5 .cse11 .cse1 .cse12) (or .cse5 .cse1 .cse9 .cse4 .cse10) (or .cse1 .cse2 .cse12 .cse3) (or .cse0 .cse5 .cse11 .cse1)))) [2022-11-19 08:28:11,703 INFO L895 garLoopResultBuilder]: At program point L80-1(lines 80 86) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse2 (= ~waterLevel~0 1)) (.cse8 (not (= 0 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse10 (not (<= |old(~waterLevel~0)| 1))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse13 (and .cse6 .cse9)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (and .cse6 .cse2 .cse3)) (or .cse7 .cse6 .cse8) (or .cse7 (not (< 1 |old(~waterLevel~0)|)) .cse9 (not (<= |old(~waterLevel~0)| 2)) .cse8) (or .cse7 (not (= |old(~waterLevel~0)| 1)) .cse2 .cse8) (let ((.cse12 (< 0 |old(~waterLevel~0)|))) (let ((.cse11 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse12))) (or .cse10 .cse0 .cse1 (and (<= ~waterLevel~0 0) (or .cse11 .cse9) .cse3 .cse4) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse6 (or (and (not .cse12) .cse9) .cse11) .cse3)))) (or .cse10 .cse7 .cse13 .cse0) (or .cse7 .cse13 .cse0 .cse5 (and .cse9 .cse4))))) [2022-11-19 08:28:11,703 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 92) no Hoare annotation was computed. [2022-11-19 08:28:11,703 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 958) no Hoare annotation was computed. [2022-11-19 08:28:11,703 INFO L895 garLoopResultBuilder]: At program point L440(lines 391 441) the Hoare annotation is: false [2022-11-19 08:28:11,704 INFO L899 garLoopResultBuilder]: For program point L428(lines 428 434) no Hoare annotation was computed. [2022-11-19 08:28:11,704 INFO L895 garLoopResultBuilder]: At program point L428-2(lines 422 435) the Hoare annotation is: (let ((.cse7 (= 0 ~systemActive~0))) (let ((.cse5 (= ~pumpRunning~0 1)) (.cse6 (= ~pumpRunning~0 0)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (< ~waterLevel~0 3)) (.cse4 (not .cse7))) (or (and .cse0 .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4 .cse5) (and .cse6 .cse2 .cse7) (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse6 .cse0 .cse1 .cse2 .cse3 .cse4)))) [2022-11-19 08:28:11,704 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-19 08:28:11,704 INFO L899 garLoopResultBuilder]: For program point L412(lines 412 418) no Hoare annotation was computed. [2022-11-19 08:28:11,704 INFO L899 garLoopResultBuilder]: For program point L412-1(lines 412 418) no Hoare annotation was computed. [2022-11-19 08:28:11,705 INFO L895 garLoopResultBuilder]: At program point L437(lines 392 439) the Hoare annotation is: (let ((.cse7 (= 0 ~systemActive~0))) (let ((.cse6 (= ~pumpRunning~0 0)) (.cse3 (< ~waterLevel~0 3)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (not .cse7)) (.cse5 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4 .cse5) (and .cse6 .cse2 .cse7) (and .cse6 .cse0 .cse1 .cse2 .cse3 .cse4) (and (= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse4 .cse5)))) [2022-11-19 08:28:11,705 INFO L895 garLoopResultBuilder]: At program point L404(line 404) the Hoare annotation is: (let ((.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse4 (< ~waterLevel~0 3)) (.cse5 (= ~pumpRunning~0 1)) (.cse0 (= ~pumpRunning~0 0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse5) (and .cse1 .cse2 .cse3 (<= 1 ~switchedOnBeforeTS~0) .cse4 .cse5) (and .cse0 .cse3 (= 0 ~systemActive~0)))) [2022-11-19 08:28:11,705 INFO L895 garLoopResultBuilder]: At program point L268(line 268) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-11-19 08:28:11,705 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-19 08:28:11,706 INFO L895 garLoopResultBuilder]: At program point L368(lines 368 375) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~4#1| 1) (= |ULTIMATE.start_main_~tmp~4#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-11-19 08:28:11,706 INFO L902 garLoopResultBuilder]: At program point L368-2(lines 368 375) the Hoare annotation is: true [2022-11-19 08:28:11,707 INFO L899 garLoopResultBuilder]: For program point L393(lines 392 439) no Hoare annotation was computed. [2022-11-19 08:28:11,707 INFO L899 garLoopResultBuilder]: For program point L422(lines 422 435) no Hoare annotation was computed. [2022-11-19 08:28:11,707 INFO L895 garLoopResultBuilder]: At program point L414(line 414) the Hoare annotation is: (let ((.cse7 (= 0 ~systemActive~0))) (let ((.cse5 (= ~pumpRunning~0 1)) (.cse6 (= ~pumpRunning~0 0)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_main_~tmp~4#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (< ~waterLevel~0 3)) (.cse4 (not .cse7))) (or (and .cse0 .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4 .cse5) (and .cse6 .cse2 .cse7) (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse6 .cse0 .cse1 .cse2 .cse3 .cse4)))) [2022-11-19 08:28:11,707 INFO L902 garLoopResultBuilder]: At program point L443(lines 382 447) the Hoare annotation is: true [2022-11-19 08:28:11,707 INFO L899 garLoopResultBuilder]: For program point L402(lines 402 408) no Hoare annotation was computed. [2022-11-19 08:28:11,707 INFO L899 garLoopResultBuilder]: For program point L402-1(lines 402 408) no Hoare annotation was computed. [2022-11-19 08:28:11,708 INFO L899 garLoopResultBuilder]: For program point L266(lines 266 272) no Hoare annotation was computed. [2022-11-19 08:28:11,708 INFO L895 garLoopResultBuilder]: At program point L266-1(lines 266 272) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-19 08:28:11,708 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 101 125) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 08:28:11,708 INFO L895 garLoopResultBuilder]: At program point L120(line 120) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 08:28:11,708 INFO L899 garLoopResultBuilder]: For program point L120-1(lines 101 125) no Hoare annotation was computed. [2022-11-19 08:28:11,709 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 101 125) no Hoare annotation was computed. [2022-11-19 08:28:11,709 INFO L895 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 .cse3) (or (not (<= ~waterLevel~0 0)) .cse1 .cse2 .cse3) (or .cse0 .cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (not (<= ~waterLevel~0 1))))) [2022-11-19 08:28:11,709 INFO L895 garLoopResultBuilder]: At program point L109(lines 109 117) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= ~pumpRunning~0 0) .cse1 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 .cse3) (or (not (<= ~waterLevel~0 0)) .cse1 .cse2 .cse3) (or .cse0 .cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (not (<= ~waterLevel~0 1))))) [2022-11-19 08:28:11,709 INFO L895 garLoopResultBuilder]: At program point L105(lines 105 122) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 08:28:11,710 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 865 876) no Hoare annotation was computed. [2022-11-19 08:28:11,710 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 865 876) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~pumpRunning~0 1))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (< |old(~waterLevel~0)| 3)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse1 .cse4 (not (= |old(~waterLevel~0)| 2)) .cse2) (or .cse0 .cse2 (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) (or .cse1 .cse4 .cse2 (not (<= 1 ~switchedOnBeforeTS~0)) .cse3))) [2022-11-19 08:28:11,710 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 179 187) no Hoare annotation was computed. [2022-11-19 08:28:11,710 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 179 187) the Hoare annotation is: true [2022-11-19 08:28:11,713 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 08:28:11,716 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-19 08:28:11,747 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 19.11 08:28:11 BoogieIcfgContainer [2022-11-19 08:28:11,747 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-19 08:28:11,748 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-19 08:28:11,748 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-19 08:28:11,748 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-19 08:28:11,749 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 08:27:18" (3/4) ... [2022-11-19 08:28:11,752 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-19 08:28:11,757 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-19 08:28:11,757 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-19 08:28:11,758 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-19 08:28:11,758 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-19 08:28:11,758 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-19 08:28:11,758 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 08:28:11,758 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-19 08:28:11,759 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-19 08:28:11,765 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 49 nodes and edges [2022-11-19 08:28:11,766 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 13 nodes and edges [2022-11-19 08:28:11,767 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-19 08:28:11,767 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 08:28:11,768 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 08:28:11,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) && (((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) [2022-11-19 08:28:11,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) [2022-11-19 08:28:11,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((((\old(waterLevel) == waterLevel && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(1 == systemActive) || (((tmp == waterLevel && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(\old(waterLevel) < 3))) && ((((((((pumpRunning == 0 && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || !(1 == systemActive)) || (((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(0 == systemActive))) || !(\old(waterLevel) == 2)) || pumpRunning == 1) [2022-11-19 08:28:11,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 08:28:11,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 08:28:11,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 08:28:11,798 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2022-11-19 08:28:11,799 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || tmp == 0) || !(waterLevel <= 1)) [2022-11-19 08:28:11,828 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/witness.graphml [2022-11-19 08:28:11,828 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-19 08:28:11,829 INFO L158 Benchmark]: Toolchain (without parser) took 54736.75ms. Allocated memory was 94.4MB in the beginning and 585.1MB in the end (delta: 490.7MB). Free memory was 59.7MB in the beginning and 248.5MB in the end (delta: -188.8MB). Peak memory consumption was 301.1MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,829 INFO L158 Benchmark]: CDTParser took 0.31ms. Allocated memory is still 94.4MB. Free memory was 68.4MB in the beginning and 68.3MB in the end (delta: 30.5kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-19 08:28:11,830 INFO L158 Benchmark]: CACSL2BoogieTranslator took 601.91ms. Allocated memory is still 94.4MB. Free memory was 59.5MB in the beginning and 61.7MB in the end (delta: -2.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,830 INFO L158 Benchmark]: Boogie Procedure Inliner took 60.39ms. Allocated memory is still 94.4MB. Free memory was 61.7MB in the beginning and 59.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,831 INFO L158 Benchmark]: Boogie Preprocessor took 29.75ms. Allocated memory is still 94.4MB. Free memory was 59.6MB in the beginning and 57.9MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,831 INFO L158 Benchmark]: RCFGBuilder took 798.32ms. Allocated memory was 94.4MB in the beginning and 113.2MB in the end (delta: 18.9MB). Free memory was 57.9MB in the beginning and 85.9MB in the end (delta: -27.9MB). Peak memory consumption was 30.4MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,832 INFO L158 Benchmark]: TraceAbstraction took 53155.71ms. Allocated memory was 113.2MB in the beginning and 585.1MB in the end (delta: 471.9MB). Free memory was 85.0MB in the beginning and 253.7MB in the end (delta: -168.7MB). Peak memory consumption was 350.2MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,832 INFO L158 Benchmark]: Witness Printer took 80.75ms. Allocated memory is still 585.1MB. Free memory was 253.7MB in the beginning and 248.5MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-19 08:28:11,834 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.31ms. Allocated memory is still 94.4MB. Free memory was 68.4MB in the beginning and 68.3MB in the end (delta: 30.5kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 601.91ms. Allocated memory is still 94.4MB. Free memory was 59.5MB in the beginning and 61.7MB in the end (delta: -2.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 60.39ms. Allocated memory is still 94.4MB. Free memory was 61.7MB in the beginning and 59.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 29.75ms. Allocated memory is still 94.4MB. Free memory was 59.6MB in the beginning and 57.9MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 798.32ms. Allocated memory was 94.4MB in the beginning and 113.2MB in the end (delta: 18.9MB). Free memory was 57.9MB in the beginning and 85.9MB in the end (delta: -27.9MB). Peak memory consumption was 30.4MB. Max. memory is 16.1GB. * TraceAbstraction took 53155.71ms. Allocated memory was 113.2MB in the beginning and 585.1MB in the end (delta: 471.9MB). Free memory was 85.0MB in the beginning and 253.7MB in the end (delta: -168.7MB). Peak memory consumption was 350.2MB. Max. memory is 16.1GB. * Witness Printer took 80.75ms. Allocated memory is still 585.1MB. Free memory was 253.7MB in the beginning and 248.5MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 958]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 53.0s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 8.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 7.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2517 SdHoareTripleChecker+Valid, 4.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2494 mSDsluCounter, 4034 SdHoareTripleChecker+Invalid, 3.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3127 mSDsCounter, 1473 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4714 IncrementalHoareTripleChecker+Invalid, 6187 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1473 mSolverCounterUnsat, 907 mSDtfsCounter, 4714 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1020 GetRequests, 732 SyntacticMatches, 9 SemanticMatches, 279 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7421 ImplicationChecksByTransitivity, 20.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=347occurred in iteration=6, InterpolantAutomatonStates: 146, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 315 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 1316 PreInvPairs, 1534 NumberOfFragments, 2414 HoareAnnotationTreeSize, 1316 FomulaSimplifications, 6080 FormulaSimplificationTreeSizeReduction, 0.7s HoareSimplificationTime, 38 FomulaSimplificationsInter, 26656 FormulaSimplificationTreeSizeReductionInter, 7.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 5.5s InterpolantComputationTime, 838 NumberOfCodeBlocks, 838 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1062 ConstructedInterpolants, 0 QuantifiedInterpolants, 3118 SizeOfPredicates, 29 NumberOfNonLiveVariables, 1403 ConjunctsInSsa, 64 ConjunctsInUnsatCore, 18 InterpolantComputations, 8 PerfectInterpolantSequences, 495/615 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 105]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: 131]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 392]: Loop Invariant Derived loop invariant: ((((((((1 == systemActive && tmp == 1) && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && !(0 == systemActive)) && pumpRunning == 1) || ((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive)) || (((((pumpRunning == 0 && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) && waterLevel < 3) && !(0 == systemActive))) || (((((2 == waterLevel && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) && pumpRunning == 1) - InvariantResult [Line: 279]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == 1) && tmp == systemActive) && waterLevel == 1 - InvariantResult [Line: 80]: Loop Invariant Derived loop invariant: (((((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1)) - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 982]: Loop Invariant Derived loop invariant: ((((((((((((((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && tmp == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive))) && (((((\old(waterLevel) == waterLevel && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 < \old(waterLevel))) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(1 == systemActive) || (((tmp == waterLevel && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && !(0 == systemActive))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((((tmp == waterLevel && \old(waterLevel) == waterLevel) && tmp == 2) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((pumpRunning == 0 && tmp == waterLevel) && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || !(\old(waterLevel) < 3))) && ((((((((pumpRunning == 0 && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && !(0 == systemActive)) || !(1 == systemActive)) || (((tmp == waterLevel && waterLevel == 1) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && !(0 == systemActive))) || !(\old(waterLevel) == 2)) || pumpRunning == 1) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: (((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == 0 && waterLevel == 1) && 1 <= switchedOnBeforeTS)) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((pumpRunning == 0 && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2)) || (\old(waterLevel) == waterLevel && pumpRunning == 1))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 382]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 289]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 958]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || tmp == 0) || !(waterLevel <= 1)) - InvariantResult [Line: 266]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: ((((((((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) && (((((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 < \old(waterLevel))) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) == 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) - InvariantResult [Line: 391]: Loop Invariant Derived loop invariant: 0 RESULT: Ultimate proved your program to be correct! [2022-11-19 08:28:11,883 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cbd8f17d-073f-49e0-bda3-f9aed38e0d8a/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE